Skip to content

The record, explained

What is an AI agent audit trail, and what should it prove?

An AI agent audit trail is a record of what each agent attempted and what was decided. It should prove that an action was authorized, not just that it happened. Proof of authorization shows that the action was permitted before it ran, which policy applied, and on whose authority. It is tamper-evident, so a later change can be detected.

AI Acts. Crelis Decides. · Runtime authorization for AI agents

The blue clay Crelis robot places a glowing card into an open drawer of a cabinet whose sealed drawers are linked by a glowing thread, while a cream clay agent looks on.
Shows
Why the action was authorized
Names
The policy and the authority
Made
At the time of the decision
Record
Tamper-evident evidence

Why it exists

Happened is not the same as authorized

An activity log records that an action happened. That is useful when a team needs to find out what an agent did, and when.

A risk team, an auditor or a customer may later ask a different question: why the action was allowed, which policy applied, and who stood behind the decision.

Proof of authorization is the record that answers those questions. It is made at the time of the decision, and it is tamper-evident, so a reader can confirm it has not been altered since.

A record that an action happened is not a record that it was authorized.

How it differs

Four records, four different questions

Each of these records is useful. They answer different questions, at different moments.

Activity log

What happened?

After the action

Trace

Which steps did the agent take?

While the agent runs

Access log

Who signed in, and what could they reach?

At sign-in

Proof of authorization

Why was this action allowed, and on whose authority?

At the time of the decision

An activity log shows what happened. Proof of authorization shows why it was allowed.

What the record shows

Three answers, one action

Proof of authorization answers three questions about one action, so the answer does not have to be pieced together later.

  1. What was decided

    The action attempted and the outcome: allow, require human approval, escalate, or block.

  2. Which policy applied

    The policy that governed the decision, named in the record.

  3. On whose authority

    Who approved the action, when policy called for a person to decide.

What regulators point to

Controls at the moment an agent acts

We publish an independent, primary-sourced reference mapping SAFR, NIST AI RMF and EU AI Act requirements to controls at AI-agent execution time. It cites the source documents and implies no endorsement.

If you are evaluating

Questions to ask of any audit trail

Pick one action an agent took last week. Then put these questions to the record it left.

  1. 01Does the record show why an action was allowed, or just that it happened?
  2. 02Does it name the policy that applied to the decision?
  3. 03When a person approves an action, does the approval become part of the record?
  4. 04If the record were changed afterwards, would the change be detectable?
  5. 05Can a past decision be reproduced from its recorded context?
  6. 06Can the record be exported and read by someone outside the team?

FAQ

Proof of authorization, in short answers

The questions people ask about AI agent audit trails.

What is an AI agent audit trail?

An AI agent audit trail is a record of what each agent attempted and what was decided. It should prove that an action was authorized, not just that it happened. Proof of authorization shows that the action was permitted before it ran, which policy applied, and on whose authority. It is tamper-evident, so a later change can be detected.

What is the difference between an AI agent audit log and an audit trail?

The terms are often used to mean the same thing. Where a distinction is drawn, an audit log is the list of events, and an audit trail is the sequence that lets a reviewer follow one action from request to outcome. Neither term, by itself, says the record shows who authorized the action.

What is proof of authorization for AI agents?

Proof of authorization is evidence that a specific AI agent action was permitted before it executed. It shows what was requested, which policy applied, what was decided, and who approved it when a person was required. It is recorded at the time of the decision and is tamper-evident.

How do you prove who authorized an AI agent action?

With a record made when the action was permitted. It names the authority the action was taken under, such as a policy or a person who approved it. It ties that authority to the one action, not to the agent in general.

What does tamper-evident mean for an AI agent audit trail?

Tamper-evident means a change to the record can be detected. It does not mean the record can never be changed. A reviewer can confirm that what they are reading is what was written at the time of the decision.

Is an AI agent audit trail the same as runtime authorization?

No. An AI agent audit trail is a record. Runtime authorization is the decision that the record is about, and it is explained on its own page. The record is what remains after the decision, so the decision can be shown later.

Does Crelis record every decision?

Yes. Every decision is written to a durable, tamper-evident record, so you can show what was decided and prove it has not been altered since. Every allowed action earns an execution visa, and every decision is recorded as proof.

Give your agents a green light — safely.

Start in shadow mode on non-production traffic. See every decision GREENLIGHT would have made — before you let it make one.