AI and Agent Controls
Agent Run Audit Record
Every agent run produces a step-by-step record of what it retrieved, which tools it called, what it changed and why. The record is available to workspace administrators and is retained with the rest of the workspace audit log.
How it is checked
Produced automatically for every run, and retained with the workspace audit log.
Framework requirements this speaks to
- ISO 27001 A.8.15 (logging)
- NIST AI RMF GOVERN 1.5
- EU AI Act Art. 12 (record-keeping)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.