Skip to content

Turn risk into a decision you can explain.

Connect the concern, the policy, and the evidence behind the response. Know what needs review and build a record that stands up to closer inspection.

Compare what the policy requires with what the record shows.

Review the work across people, systems, and AI agents. Keep the decision, its supporting evidence, and the limits of your coverage together.

Find the record that answers your review question.

An exception, a changed commitment, a gap in oversight. Start with the question you need to resolve and inspect what the evidence supports.

Policy exception

A held request is not an approved action.

Follow the request to the rule and recorded decision. Confirm whether approval or execution appears in the history before drawing a conclusion.

Request
Support agent requested a $900 refund.
Applicable policy
Refunds above $500 require an authorized reviewer’s approval.
Decision record
Held for approval. No subsequent approval or execution in this record.
What the record supports

The record supports a hold. It does not establish that the refund was approved or issued.

Check the approval history and any later action record.

Make the control part of the decision.

Turn supported policies into checks on governed actions. Hold exceptions for an authorized reviewer with the request, rule, and evidence attached.

A required check that cannot be completed keeps the action held. Policy versions and review decisions stay on record so a later investigation can follow the basis at the time.

Explore policies and approvals
Approval review

Review the request against its governing rule.

Bring the proposed action and its governing rule into the same review.

RequestActor, action, and scope
RulePolicy version in force
EvidenceSources and open questions
Approval does not bypass other permissions or operating limits.

The gaps belong in the review, too.

Separate the controls applied before execution from activity recorded afterward. Keep missing evidence visible instead of treating silence as assurance.

Enforced.

A request passed through the governance path before execution. Inspect the verdict, applicable policy, and any required approval.

Review the decision and its basis

Observed.

Activity arrived through a log or another record after it happened. It can support reconstruction without establishing prior enforcement.

Review the source and its limits

Not evidenced.

The available record does not establish the control. Identify what is missing and what additional evidence the review needs.

Keep the unresolved question visible

Record integrity and control effectiveness are separate questions. A valid proof does not turn observed activity into enforced oversight.

Orcinta Attest

Prepare a record with a clearly defined scope.

Bring receipts, reconstruction, coverage, and control mappings into a conformance packet. Choose the organization or agent and the period under review.

Share a branded export and a shareable verification link that you can revoke. Give reviewers a bounded record they can check, with missing evidence and verification limits included.

Explore conformance packets

Connect evidence to the control in question.

Use versioned reference mappings to organize the review. Follow a control to the available evidence and assess what it establishes.

Mappings support review; they do not certify compliance. Each control needs its own evidence, context, and judgment.

Explore the control catalog

NIST AI RMF

Reference mapping

Accountability, decision basis, inventory, and oversight.

ISO/IEC 42001

Reference mapping

Event logging, system records, and human oversight.

EU AI Act

Reference mapping

Traceability, oversight, deployer records, and transparency.

Have questions?

What can risk and compliance teams review?

Review material operational concerns, governed decisions, agent activity, and the evidence behind them. Follow a concern to its sources, examine the policy and approval history available for an action, and reconstruct what was known at the time. Coverage depends on connected sources, permissions, and enabled capabilities.

Does this cover people as well as AI agents?

Yes. The organizational record connects work across people, systems, and connected AI agents. Supported actions routed through the governed path use shared policy and permission checks. Agent activity imported after execution remains observed evidence and cannot be blocked retroactively.

What does a conformance packet include?

With Attest available, an authorized user can assemble a packet scoped to an organization or agent and a time window. It brings together receipts, the available reconstruction, integrity information, governance coverage, and versioned control mappings. Missing evidence and coverage limits remain part of the record. Generation and export follow the applicable permissions.

Does a verified receipt establish that an action was compliant?

No. Receipt verification establishes properties of the recorded evidence, including integrity, attribution, and ordering. It does not establish that the action was correct, every relevant event was captured, or a regulatory requirement was satisfied. A review still needs the underlying context and the applicable obligations.

Which frameworks have control mappings?

The versioned catalog maps selected evidence to controls in NIST AI RMF, ISO/IEC 42001, and the EU AI Act. These are advisory reference mappings, not certifications or legal attestations. Evidence is assessed per control; a framework mapping does not mean every control is evidenced. The catalog separately identifies other frameworks with architectural alignment.

How do later changes affect an earlier review?

Every fact carries two dates: when it took effect and when it reached the record. Later evidence can update the current picture while preserving earlier knowledge. Policy versions and original receipts remain available, so reconstruction can examine the decision in its historical context. If that context cannot be established, the gap stays visible.

Can an external reviewer check a packet?

A packet can include a shareable verification link that works without signing in. The link exposes limited verification information, not access to the workspace. An authorized user can revoke the packet so its link no longer returns a verified result. Revocation does not recall files already downloaded.

Bring the evidence into your next review.

Connect the risk, the response,
and the record behind your next review.

We do not currently use analytics or advertising cookies. Cookie policy · Privacy policy