An audit-ready evidence pack#
Your auditor asks how your agents were governed last quarter. You will make sure the records are kept long enough, give the auditor their own read-only access, produce a signed evidence pack for the quarter, and show them how to check it — and any receipt in it — without trusting you or Astralyx's console.
Before you begin#
- The workspace's admin role.
- The auditor has an account in your organisation.
1. Keep the records long enough#
By default, finished approvals are kept 7 days and machines keep traces 7 days after a run is gone from them; runs, receipts and packs are kept. For an annual audit, keep approvals and runs at least a year and a quarter:
Retention (in the workspace's menu): Finished approvals 460,
Finished runs and their history 460, Traces, activity and
receipts' lines 30; leave Receipts and Evidence packs empty
(kept). Save.
Retention cannot bring back what was already removed: set it before the period you will be audited on.
2. Give the auditor access#
In the workspace's settings, give the auditor the auditor role. They read the governance record — agents and versions, runs, receipts, costs, approvals, guardrails, budgets, flows, eval runs, retention — but not workloads, logs, traces, suites' cases or what a held call would send; and they may make and download evidence packs. See Roles and permissions.
3. Make the pack#
Anemoi → Evidence packs → New evidence pack: name q3-2026,
Scope The whole workspace, From 2026-07-01, To (inclusive)
2026-09-30, every section. Wait for Ready (activity is asked of the
machines that ran the runs: allow a couple of minutes).
$ curl -sS -X POST "$WS/evidence-packs" -H "Authorization: Bearer $ASTRA_TOKEN" -H "Content-Type: application/json" \
-d '{"metadata": {"name": "q3-2026"}, "spec": {"scope": "workspace", "from": "2026-07-01T00:00:00Z", "to": "2026-09-30T23:59:59Z"}}'
$ curl -sS "$WS/evidence-packs/q3-2026" -H "Authorization: Bearer $ASTRA_TOKEN" | jq '.status.state, (.manifest.manifest.files // [] | length)'
For one agent's record only, use the scope agent:<name>.
4. Download and check it#
$ curl -sS "$WS/evidence-packs/q3-2026/download" -H "Authorization: Bearer $ASTRA_TOKEN" -o q3-2026.zip
$ curl -sS "$WS/identity/jwks" -H "Authorization: Bearer $ASTRA_TOKEN" -o jwks.json
$ astra evidence verify q3-2026.zip --jwks jwks.json
The auditor should save jwks.json once, at the start of the
engagement, and check every pack against that copy: then a pack verifies
only if the cluster they trusted signed it. Checked against the
jwks.json inside the pack, it shows only that the pack is whole.
5. Walk the auditor through it#
| Question | Where |
|---|---|
| What could the agents do? | agents.json (every version: kind, model, tools, sandbox, budget, instructions' digest) and policies.json (tool and sandbox policies, guardrails, digests). |
| Who approved risky actions? | approvals.json: what was asked, of whom, who decided, when, why. |
| What did each run do? | receipts.json: one signed receipt per run, verified against the cluster's keys when the pack was made. |
| Were changes tested? | evals.json: suites, verdicts, the gate, promotions, traffic splits, rollbacks. |
| Was spending controlled? | budgets.json. |
| Did anything reach where it should not? | activity.json: per run, hosts reached and refusals. |
| What changed, when? | events.jsonl. |
| Which control does each answer? | controls.md: EU AI Act Articles 9, 12, 13 and 14; SOC 2 CC6, CC7 and CC8 — with its note that it is not legal advice. |
To go further on one run, give the auditor its receipt and exported steps and let them check it themselves (Verify a receipt): the receipt's chain shows no run of that agent was dropped between two receipts.
The pack holds metadata and digests only — no prompt, answer, tool argument or request body — so it can leave your organisation.