25 September 2025 / Applied AI / 9 chapters

Verify one complete and one broken run

From Designing an audit trail for tool-using agents

Before release, create a production-like task that reads controlled private records, produces a proposal, receives approval and performs a reversible external change. Follow it through every event and compare the audit view with source-system logs.

Check that the trail contains the task and run identities, requesting actor, workload credential, instruction and tool versions, source object versions, tool arguments after redaction, policy results, proposal hash, approval, executed payload and destination receipt.

Then interrupt a second run after the action request leaves but before the local acknowledgement is stored. The task should remain unresolved. Reconcile it through the destination, record the outcome and confirm the recovery view clears only after evidence arrives.

Run boundary cases as well: denied cross-scope read, truncated search, stale target version, expired approval, edited proposal, replayed action ID, secret in a tool error and deletion of retained prompt content. Inspect both what the system records and what it refuses to record.

Finally, ask an operator who did not build the workflow to answer the opening review questions using only the authorised audit views and linked source records. Any answer that depends on developer memory points to a missing event, an unclear status or a view that still needs work.

All articles