Evidence packs and retention#
An auditor asks: what were your agents allowed to do, who approved what, what did they spend, how were changes tested? An evidence pack answers for a period, in one ZIP whose manifest is signed by the cluster and can be checked offline. Retention says how long each record is kept.
What a pack holds#
A pack covers the workspace or one agent, from a date to a date (at most 400 days), and these sections (all by default):
| Section | File | Holds |
|---|---|---|
agents |
agents.json |
Each version's specification — kind, model, tools, sandbox, budget — with a digest of its instructions (not their text), who wrote it and when. Tools' URLs without their query; fixed headers by name. |
policies |
policies.json |
Each version's tool and sandbox policies and the workspace's guardrails, with their digests. |
approvals |
approvals.json |
Each approval: target (without query), approvers, decision, who, when, why. Never the call's arguments. |
receipts |
receipts.json |
Each run's receipt, verified against the cluster's keys. |
budgets |
budgets.json |
Budgets and what was spent. |
evals |
evals.json |
Suites (how many cases and graders, their digest — not the cases), eval runs and verdicts, the gate, promotions, traffic and rollbacks. |
flows |
flows.json |
Executions: steps' states, attempts and reasons — not their inputs, outputs or events' data. |
activity |
activity.json |
Each run's activity summary from its machine: counts, bytes, hosts, refusals — never an entry. |
events |
events.jsonl |
State changes of agents, runs, approvals, budgets, flows and evaluations. |
Every pack also has controls.json and controls.md, which map each
section to what an auditor asks — EU AI Act Articles 9 (risk management),
12 (record-keeping), 13 (transparency) and 14 (human oversight); SOC 2
CC6, CC7 and CC8 — with a note that this is not legal advice; and
manifest.json (each file's SHA-256), manifest.jws (the cluster's
signature) and jwks.json (the cluster's public keys).
Metadata and digests only: never prompts, answers, tool arguments or the contents of requests. A pack is at most 64 MiB; activity is asked of at most 500 runs' machines, for at most 2 minutes — runs left are marked not fetched.
Signed and checkable offline#
astra evidence verify pack.zip --jwks jwks.json checks the manifest, its
signature, each file's SHA-256, and that no file is missing or added. With
the jwks.json inside the pack it shows the pack is whole; with keys you
saved from the cluster when you trusted it, it shows the pack is the
cluster's. See Export an evidence pack.
Packs are made and downloaded by the workspace's admins and auditors; a workspace keeps at most 100.
Retention#
Each workspace has one retention policy, set by its admins under Retention (days; unset is the default):
| Field | Applies to | Default |
|---|---|---|
machine_traces_days |
On machines: traces, activity and receipts' step lines of runs no longer on the machine | 7 |
runs_days |
Finished agent runs, flow executions and eval runs, with their history | kept |
approvals_days |
Finished approvals | 7 |
evidence_packs_days |
Evidence packs | kept |
receipts_days |
Receipts | kept. When set: at least 30, and at least evidence_packs_days, which must then be set too |
Each is 1 to 3 660 days (ten years). The console's Retention page also sets how long the workspace's event history is kept. Every change is recorded with who made it.
Warning
A trace exported after its machine dropped it cannot be checked
against its receipt. Export what you must keep before
machine_traces_days passes, or raise it.