Skip to content

Evidence packs and retention#

An auditor asks: what were your agents allowed to do, who approved what, what did they spend, how were changes tested? An evidence pack answers for a period, in one ZIP whose manifest is signed by the cluster and can be checked offline. Retention says how long each record is kept.

What a pack holds#

A pack covers the workspace or one agent, from a date to a date (at most 400 days), and these sections (all by default):

Section File Holds
agents agents.json Each version's specification — kind, model, tools, sandbox, budget — with a digest of its instructions (not their text), who wrote it and when. Tools' URLs without their query; fixed headers by name.
policies policies.json Each version's tool and sandbox policies and the workspace's guardrails, with their digests.
approvals approvals.json Each approval: target (without query), approvers, decision, who, when, why. Never the call's arguments.
receipts receipts.json Each run's receipt, verified against the cluster's keys.
budgets budgets.json Budgets and what was spent.
evals evals.json Suites (how many cases and graders, their digest — not the cases), eval runs and verdicts, the gate, promotions, traffic and rollbacks.
flows flows.json Executions: steps' states, attempts and reasons — not their inputs, outputs or events' data.
activity activity.json Each run's activity summary from its machine: counts, bytes, hosts, refusals — never an entry.
events events.jsonl State changes of agents, runs, approvals, budgets, flows and evaluations.

Every pack also has controls.json and controls.md, which map each section to what an auditor asks — EU AI Act Articles 9 (risk management), 12 (record-keeping), 13 (transparency) and 14 (human oversight); SOC 2 CC6, CC7 and CC8 — with a note that this is not legal advice; and manifest.json (each file's SHA-256), manifest.jws (the cluster's signature) and jwks.json (the cluster's public keys).

Metadata and digests only: never prompts, answers, tool arguments or the contents of requests. A pack is at most 64 MiB; activity is asked of at most 500 runs' machines, for at most 2 minutes — runs left are marked not fetched.

Signed and checkable offline#

astra evidence verify pack.zip --jwks jwks.json checks the manifest, its signature, each file's SHA-256, and that no file is missing or added. With the jwks.json inside the pack it shows the pack is whole; with keys you saved from the cluster when you trusted it, it shows the pack is the cluster's. See Export an evidence pack.

Packs are made and downloaded by the workspace's admins and auditors; a workspace keeps at most 100.

Retention#

Each workspace has one retention policy, set by its admins under Retention (days; unset is the default):

Field Applies to Default
machine_traces_days On machines: traces, activity and receipts' step lines of runs no longer on the machine 7
runs_days Finished agent runs, flow executions and eval runs, with their history kept
approvals_days Finished approvals 7
evidence_packs_days Evidence packs kept
receipts_days Receipts kept. When set: at least 30, and at least evidence_packs_days, which must then be set too

Each is 1 to 3 660 days (ten years). The console's Retention page also sets how long the workspace's event history is kept. Every change is recorded with who made it.

Warning

A trace exported after its machine dropped it cannot be checked against its receipt. Export what you must keep before machine_traces_days passes, or raise it.