Learn · Governance
How to audit every action an AI agent takes
Most agent logs record a token and call it an audit trail. But a token is just a string anyone could have copied. A real audit trail proves which agent acted, under whose authority, in evidence you can verify after the fact.
Why token logs aren't enough
A log line that says "request authenticated with token T" tells you a valid token was presented. It does not tell you the request genuinely came from the agent the token names, because a token read out of a log or copied from memory would produce the same line. If your audit evidence is a bearer token, your evidence is only as good as the assumption that the token was never copied — which is exactly the assumption an incident calls into question. For agents, bearer-token logging is attribution theatre.
Attribution you can re-verify
Provable attribution means each action is accompanied by a signature made by a private key that never leaves the agent's host, over the exact operation requested. Later, anyone with the public key can re-verify that this specific action was signed by this specific agent — no trust in the log pipeline required. The identity is sender-constrained, so a copied token cannot reproduce the signature. The result is evidence rather than a claim: you can hand an auditor a record and they can check the math themselves.
The test of an audit trail is whether it survives the question "could someone have faked this?" A signed, sender-constrained proof survives it; a logged bearer token does not.
What to record
- Agent identity — the verified, unique identity that signed the request, not a shared key.
- Human owner — the named person who enrolled the agent, from the enrolment record.
- Operation and resource — exactly what was requested and against what.
- Decision and policy version — allow or deny, and the policy that made the call.
- Signature and timestamp — the proof itself, re-verifiable later, and when it happened.
How to set it up
- Sign every request. Use per-agent keys and request signing (RFC 9421) so each action carries a verifiable proof. See per-agent identity.
- Decide and log at the gateway. Record the verified identity, operation, decision, and policy version together.
- Retain the proofs. Keep the signatures so decisions can be re-verified independently.
- Tie back to ownership. Join each action to the enrolment record for the responsible human.
OATHERA writes tamper-evident, attributed decision logs by design. See the security overview.
FAQ
How do you audit every action an AI agent takes in a way that proves the identity behind each request, not just logs a token?
Have each agent sign every request with a private key that never leaves its host, over the exact operation, and record that signature alongside the verified identity, the human owner, the operation and resource, and the policy decision. Because the signature is sender-constrained and re-verifiable, the log proves which agent acted rather than merely recording a token that could have been copied.
What is wrong with logging the token on each request?
A token is a bearer string; a copy of it produces an identical log line. If your audit evidence is a token, it cannot distinguish the real agent from anyone who obtained the token. A signature from a non-exportable key can.
Can an auditor verify the trail without trusting our logging pipeline?
Yes. Because each action is signed by the agent's key, anyone with the corresponding public key can re-verify that the specific action was signed by the specific agent, independent of how the log was stored.