Skip to content

Export an evidence pack#

An evidence pack is the governance record of a workspace, or of one agent, over a period: agent versions, policies, approvals, receipts, budgets, evaluations, flows, activity summaries and events, in a ZIP whose manifest the cluster signs. This page covers asking for one, downloading it, checking it, and setting retention. What a pack holds is in Evidence packs and retention.

Before you begin#

  • The workspace's admin or auditor role. An admin can make someone an auditor in the workspace's settings: auditors read the governance record without workloads, logs or traces.
  • astra on the computer that checks (Install the CLI).
  • For the API: ASTRA_TOKEN and WS as in the REST API page.

Ask for a pack#

  1. Open Anemoi → Evidence packs and press New evidence pack.
  2. Name (lowercase letters, digits and -, at most 63), Scope (The whole workspace or one agent), From and To (inclusive), and the Sections (all by default).
  3. Confirm. The pack is Pending, then Building, then Ready (or Failed, with the reason).
$ curl -sS -X POST "$WS/evidence-packs" -H "Authorization: Bearer $ASTRA_TOKEN" \
    -H "Content-Type: application/json" \
    -d '{"metadata": {"name": "q3-2026"}, "spec": {"scope": "workspace", "from": "2026-07-01T00:00:00Z", "to": "2026-09-30T23:59:59Z"}}'
$ curl -sS "$WS/evidence-packs/q3-2026" -H "Authorization: Bearer $ASTRA_TOKEN" | jq .status.state
"Ready"

scope is workspace or agent:<name>; include lists sections (agents, policies, approvals, receipts, budgets, evals, flows, activity, events), all when absent. The period is at most 400 days. A workspace keeps at most 100 packs.

Download and check it#

On the pack: Download .zip, and The cluster's keys (jwks.json) — save the keys once, when you trust the cluster. The page lists the files with their size and SHA-256, the signed manifest, and the command to check it.

$ curl -sS "$WS/evidence-packs/q3-2026/download" -H "Authorization: Bearer $ASTRA_TOKEN" -o q3-2026.zip
$ curl -sS "$WS/identity/jwks" -H "Authorization: Bearer $ASTRA_TOKEN" -o jwks.json
$ astra evidence verify q3-2026.zip --jwks jwks.json

It prints the pack, its scope and period, one line per check — manifest (it parses, its format), signature (by the keys given), files (each file's SHA-256, none missing or added) — and verified or NOT verified; the exit status is 1 when a check failed. --json prints {ok, checks, manifest}; --cluster <url> fetches the keys from <url>/v1/identity/jwks instead of --jwks. Without either, the pack's own jwks.json is used: that shows the pack is whole, not that it is the cluster's.

GET $WS/evidence-packs/{name}/download answers the ZIP (application/zip), or 409 EVIDENCE_PACK_NOT_READY before it is Ready. GET $WS/evidence-packs lists them; DELETE removes one (downloaded copies stay valid).

Inside the ZIP: one file per section, controls.json and controls.md (which control each section answers), manifest.json, manifest.jws and jwks.json.

Set retention#

Open Retention (in the workspace's menu), set the days for each kind of record — or leave one empty for the default — and press Save. Changes lists who changed what. Admins only.

$ curl -sS -X PUT "$WS/retention-policies/default" -H "Authorization: Bearer $ASTRA_TOKEN" \
    -H "Content-Type: application/json" \
    -d '{"spec": {"machine_traces_days": 30, "approvals_days": 365, "evidence_packs_days": 2555, "receipts_days": 2555}}'

The fields are in Evidence packs and retention. Each is 1 to 3 660 days. receipts_days needs evidence_packs_days and is at least that, and at least 30. DELETE goes back to the defaults.