Export an evidence pack#
An evidence pack is the governance record of a workspace, or of one agent, over a period: agent versions, policies, approvals, receipts, budgets, evaluations, flows, activity summaries and events, in a ZIP whose manifest the cluster signs. This page covers asking for one, downloading it, checking it, and setting retention. What a pack holds is in Evidence packs and retention.
Before you begin#
- The workspace's admin or auditor role. An admin can make someone an auditor in the workspace's settings: auditors read the governance record without workloads, logs or traces.
astraon the computer that checks (Install the CLI).- For the API:
ASTRA_TOKENandWSas in the REST API page.
Ask for a pack#
- Open Anemoi → Evidence packs and press New evidence pack.
- Name (lowercase letters, digits and
-, at most 63), Scope (The whole workspace or one agent), From and To (inclusive), and the Sections (all by default). - Confirm. The pack is
Pending, thenBuilding, thenReady(orFailed, with the reason).
$ curl -sS -X POST "$WS/evidence-packs" -H "Authorization: Bearer $ASTRA_TOKEN" \
-H "Content-Type: application/json" \
-d '{"metadata": {"name": "q3-2026"}, "spec": {"scope": "workspace", "from": "2026-07-01T00:00:00Z", "to": "2026-09-30T23:59:59Z"}}'
$ curl -sS "$WS/evidence-packs/q3-2026" -H "Authorization: Bearer $ASTRA_TOKEN" | jq .status.state
"Ready"
scope is workspace or agent:<name>; include lists sections
(agents, policies, approvals, receipts, budgets, evals,
flows, activity, events), all when absent. The period is at most
400 days. A workspace keeps at most 100 packs.
Download and check it#
On the pack: Download .zip, and The cluster's keys (jwks.json) — save the keys once, when you trust the cluster. The page lists the files with their size and SHA-256, the signed manifest, and the command to check it.
$ curl -sS "$WS/evidence-packs/q3-2026/download" -H "Authorization: Bearer $ASTRA_TOKEN" -o q3-2026.zip
$ curl -sS "$WS/identity/jwks" -H "Authorization: Bearer $ASTRA_TOKEN" -o jwks.json
$ astra evidence verify q3-2026.zip --jwks jwks.json
It prints the pack, its scope and period, one line per check —
manifest (it parses, its format), signature (by the keys given),
files (each file's SHA-256, none missing or added) — and verified
or NOT verified; the exit status is 1 when a
check failed. --json prints {ok, checks, manifest}; --cluster
<url> fetches the keys from <url>/v1/identity/jwks instead of
--jwks. Without either, the pack's own jwks.json is used: that
shows the pack is whole, not that it is the cluster's.
GET $WS/evidence-packs/{name}/download answers the ZIP
(application/zip), or 409 EVIDENCE_PACK_NOT_READY before it is
Ready. GET $WS/evidence-packs lists them; DELETE removes one
(downloaded copies stay valid).
Inside the ZIP: one file per section, controls.json and controls.md
(which control each section answers), manifest.json, manifest.jws and
jwks.json.
Set retention#
Open Retention (in the workspace's menu), set the days for each kind of record — or leave one empty for the default — and press Save. Changes lists who changed what. Admins only.
$ curl -sS -X PUT "$WS/retention-policies/default" -H "Authorization: Bearer $ASTRA_TOKEN" \
-H "Content-Type: application/json" \
-d '{"spec": {"machine_traces_days": 30, "approvals_days": 365, "evidence_packs_days": 2555, "receipts_days": 2555}}'
The fields are in Evidence packs and retention.
Each is 1 to 3 660 days. receipts_days needs evidence_packs_days
and is at least that, and at least 30. DELETE goes back to the
defaults.