Enforced.
A request passed through the governance path before execution. Inspect the verdict, applicable policy, and any required approval.
Review the decision and its basisConnect the concern, the policy, and the evidence behind the response. Know what needs review and build a record that stands up to closer inspection.
Review the work across people, systems, and AI agents. Keep the decision, its supporting evidence, and the limits of your coverage together.
An exception, a changed commitment, a gap in oversight. Start with the question you need to resolve and inspect what the evidence supports.
Follow the request to the rule and recorded decision. Confirm whether approval or execution appears in the history before drawing a conclusion.
The record supports a hold. It does not establish that the refund was approved or issued.
Check the approval history and any later action record.
Turn supported policies into checks on governed actions. Hold exceptions for an authorized reviewer with the request, rule, and evidence attached.
A required check that cannot be completed keeps the action held. Policy versions and review decisions stay on record so a later investigation can follow the basis at the time.
Explore policies and approvalsBring the proposed action and its governing rule into the same review.
Separate the controls applied before execution from activity recorded afterward. Keep missing evidence visible instead of treating silence as assurance.
A request passed through the governance path before execution. Inspect the verdict, applicable policy, and any required approval.
Review the decision and its basisActivity arrived through a log or another record after it happened. It can support reconstruction without establishing prior enforcement.
Review the source and its limitsThe available record does not establish the control. Identify what is missing and what additional evidence the review needs.
Keep the unresolved question visibleRecord integrity and control effectiveness are separate questions. A valid proof does not turn observed activity into enforced oversight.
Bring receipts, reconstruction, coverage, and control mappings into a conformance packet. Choose the organization or agent and the period under review.
Share a branded export and a shareable verification link that you can revoke. Give reviewers a bounded record they can check, with missing evidence and verification limits included.
Explore conformance packetsUse versioned reference mappings to organize the review. Follow a control to the available evidence and assess what it establishes.
Mappings support review; they do not certify compliance. Each control needs its own evidence, context, and judgment.
Explore the control catalogAccountability, decision basis, inventory, and oversight.
Event logging, system records, and human oversight.
Traceability, oversight, deployer records, and transparency.
Review material operational concerns, governed decisions, agent activity, and the evidence behind them. Follow a concern to its sources, examine the policy and approval history available for an action, and reconstruct what was known at the time. Coverage depends on connected sources, permissions, and enabled capabilities.
Yes. The organizational record connects work across people, systems, and connected AI agents. Supported actions routed through the governed path use shared policy and permission checks. Agent activity imported after execution remains observed evidence and cannot be blocked retroactively.
With Attest available, an authorized user can assemble a packet scoped to an organization or agent and a time window. It brings together receipts, the available reconstruction, integrity information, governance coverage, and versioned control mappings. Missing evidence and coverage limits remain part of the record. Generation and export follow the applicable permissions.
No. Receipt verification establishes properties of the recorded evidence, including integrity, attribution, and ordering. It does not establish that the action was correct, every relevant event was captured, or a regulatory requirement was satisfied. A review still needs the underlying context and the applicable obligations.
The versioned catalog maps selected evidence to controls in NIST AI RMF, ISO/IEC 42001, and the EU AI Act. These are advisory reference mappings, not certifications or legal attestations. Evidence is assessed per control; a framework mapping does not mean every control is evidenced. The catalog separately identifies other frameworks with architectural alignment.
Every fact carries two dates: when it took effect and when it reached the record. Later evidence can update the current picture while preserving earlier knowledge. Policy versions and original receipts remain available, so reconstruction can examine the decision in its historical context. If that context cannot be established, the gap stays visible.
A packet can include a shareable verification link that works without signing in. The link exposes limited verification information, not access to the workspace. An authorized user can revoke the packet so its link no longer returns a verified result. Revocation does not recall files already downloaded.
Connect the risk, the response,
and the record behind your next review.