Governance

Governance evidence for AI agent workflows

Akretic records policy decisions, approvals, denials, retrieval releases, egress checks, and material tool actions so security and compliance teams can review what happened.

Iron Ledger

Evidence supports investigation, review, and policy tuning.

Akretic's evidence plane is designed to create a tamper-evident record of material decisions and actions. It is not a substitute for a customer's compliance program, legal review, or regulatory reporting obligations.

Evidence Type

Tamper-evident

Purpose

Review support

evidence-event
event: policy_decision
identity_context: authenticated_enterprise_user
retrieval_source: approved_knowledge_base
decision: allow_with_evidence
review_state: recorded
operator_output: design_partner_review_finding

Framework Mapping

Mapping support during pilot scoping.

Framework mappings are planning inputs for pilot scoping, not certification, legal attestation, or compliance status.

Records-retention review

Tamper-evident evidence designed to support review.

Mapping support during pilot scoping
Regulated data access workflows

Policy and retrieval controls can be mapped during pilot scoping.

Pilot scoping
NIST 800-53

Identity, authorization, audit, and access-control mapping support.

Assessment dependent
Operational resilience review

Approval and evidence paths for selected high-risk actions.

Pilot scoping
Financial services review

Evidence support for approvals, denials, retrieval releases, and action events.

Mapping support during pilot scoping
EU AI Act Art. 12 and 14

Logging and human-review mapping support.

Assessment dependent

Retrieval And Action Review

Neutral evidence examples for internal assistant workflows.

Observation Mode records what sources and actions were observed, filtered, reviewed, marked for approval, or recorded for follow-up.

Observation Matrix
approved_knowledge_baseobservable
restricted_source_groupfiltered
external_fetch_domainreviewed
sensitive_actionapproval_candidate
audit_eventrecorded

Identity Boundary

Authenticated context, not model output.

Supported Akretic paths bind requests to authenticated enterprise identity and policy context. Identity, group, and tenant handling must be derived from authenticated context in production deployments, not from model output or caller-supplied claims.

identity-policy-context
authenticated_identity: enterprise_user
group_context: source_of_truth_directory
tenant_context: deployment_scope
model_output: not_authoritative
policy_decision: externalized