What an AI agent audit trail cannot tell you

An AI agent audit trail shows what was recorded, not what happened in full. Silence in the trail does not prove that nothing occurred off the record, that scope was well chosen, or that outcomes were fair. Honest operators publish what they intend to instrument, label what each record actually supports, and say plainly which questions the trail cannot settle on its own.

What a trail can support

A well-built audit trail helps a sceptical reader reconstruct material actions that were captured: who or what acted, when, under which declared configuration, with what authority, and with what outcome signals. Append-only storage with tamper-evident linking makes missing or altered entries easier to detect than in a mutable log. Where scope is declared upfront, readers can compare recorded actions against the list of actions the operator said would be instrumented. Evidence levels, when labelled honestly, answer a narrow but important question: who or what produced each line of the record.

These are reconstruction aids. They support due diligence conversations. They do not, by themselves, settle broader questions about trustworthiness or fit for purpose.

What a trail cannot settle alone

Unrecorded activity. Shadow tools, manual workarounds, out-of-band messages, or actions taken before instrumentation existed leave no line in the trail. A clean-looking room can mean good behaviour, or that awkward steps were never logged.

Whether scope was the right scope. Declaring allowed and prohibited actions is valuable structure. It does not show that the boundary was wise, complete, or aligned with buyer expectations.

Quality, fairness, or correctness of outcomes. A record that an agent sent an email does not show the email was accurate, kind, or lawful. System-confirmed references show that an external object existed, not that the underlying decision was sound.

Complete instrumentation. Unless the operator publishes what event types and critical actions should produce receipts, silence on a topic is ambiguous: nothing happened, or nobody logged that class of event.

Continuous human attention. Operator-confirmed steps show a named human resolved a specific queued action. They do not show the operator was engaged between those moments, or that every autonomous step was reviewed.

Environmental integrity. Configuration fingerprints bind an event to a declared version of the agent. They do not prove the hosting environment was untampered, nor that undocumented side channels were absent.

Declared but never recorded

The most useful honesty signal in a scoped trail is the gap between declared and recorded. If a use case lists allowed actions and one of them has never produced a receipt, that is a structural fact about coverage, not an estimate of unreported activity. Proofroom surfaces such gaps as "declared but never recorded" on live proof rooms. That label does not accuse the agent of wrongdoing. It states that the operator said this action class mattered, and the trail has no entry for it yet.

Readers should treat undeclared silence as the dangerous case: if you never said you would log refunds, absence of refund receipts proves nothing either way.

Decay, freshness, and platform gaps

Time since the last material event is itself a signal. A room that stopped emitting events should not look perpetually current. Conversely, if the recording platform itself was unavailable, a quiet period might reflect outage rather than agent inactivity. Honest designs separate agent silence from recorder silence where possible.

How Proofroom approaches this

Proofroom treats absence of evidence as first-class information, not something to paper over. Use case passports declare allowed actions, prohibited actions, oversight, and a decay window. Live proof rooms list any declared allowed action that has never produced a receipt. Every Action Receipt carries a mandatory note on what the record does not establish. The product never estimates or infers unreported activity: gaps are named structurally, not filled with guesses.

Platform intake incidents are recorded publicly at /status. While an incident is open, evidence decay pauses so platform downtime is not displayed as the agent going quiet. See Outage-safe decay for the mechanism.

Recording is fire-and-forget by default. If Proofroom is unreachable, the agent continues without blocking. That design choice means completeness depends on the agent's instrumentation path, not on the recorder always being present. Operators who need stronger durability for specific actions can opt into require_ack for those steps; that trades independence for an acknowledgement that a row was written.

Related pages