ANSWER

How do you audit what an AI agent did?

Reviewed .

To audit an AI agent, require an execution-time record for every action: who executed it, what changed, when it happened, which data was involved and which rule authorized it. The record must also separate autonomous work from actions awaiting human approval. A report reconstructed later is not an audit trail.

Step by step

  • Record each action at execution time.
  • Include the applied rule, not only the result.
  • Separate autonomous execution from human approval.
  • Provide an operator-accessible kill switch.
  • Ensure the trail remains exportable after the vendor relationship ends.

How an agent does this

AgenticosCore combines the Trail, House Rules and the one-click Brake. Together they show what ran, what waited and how execution can be stopped without opening a ticket.

Frequently asked questions

Do I keep the trail after termination?

Yes. Your operational records remain exportable.

Who is the data controller?

The allocation depends on actual purposes, decisions and activities. It must be recorded for the concrete processing; a generic vendor label is not enough.

Primary sources