Docs / AMS / Govern / Audit
View as MarkdownAudit
Check your protections, find who did what and when, ask the Audit Agent, and export an evidence pack for a framework.
After this page, you can show an auditor what your agents did and what protects them. You can answer "who changed the invoice exceptions agent last Tuesday, and what changed?", check that the record is intact, and hand over an evidence pack for a framework such as SOC 2.
What this is
Govern → Audit is the org's audit trail and the protections behind it. Only org admins can open it. Nothing on it is authored: Mindset writes each record the moment something happens, and an agent can't skip that.
The trail is append only. The audit database refuses updates and deletes, and each record is hash-chained to the one before it, so a change anywhere would show.
Audit has four tabs, in this order:
| Tab | The question it answers |
|---|---|
| Posture | Am I protected? |
| Personal data | What is being caught, by what rule, and what happened to it? |
| Obligations | What am I claiming, and can I prove it? |
| Record | What happened? |
The Audit Agent panel sits on the left of every tab.
Posture
One card per protection: whether it's on right now, what it has caught or checked lately, and where it's set. The cards are Personal data, Data residency, Audit record, Audit retention and What we look for. Nothing here can be changed. Each card links to the setting that owns it.
Re-verify now reads the record again and re-derives the hash chain. It changes nothing. There is no overall score.
Personal data
What personal data was caught, by which rule, and whether the real value was restored. The value itself is never shown, at any policy setting, to anyone. To change what's caught or how it's handled, go to Settings → Governance. See Personal data.
Record
Every consequential act in the org: who did it, what changed and when. That includes creates, changes, publishes, archives and deletes, and deliberate reads such as an audit export.
- Filter with the chips: All actions, Function runs, Function outbound calls, Function model calls, Personal data and Governance changes.
- Read the table: When, Action, Actor, Channel, Subject and Outcome. The actor carries a role: user, agent, API key or Mindset operator.
- Open a row to see What changed, The turn, Integrity and Raw. Integrity shows the record's hash and the record it chains to.
An agent's internal model calls and tool calls go to Govern → Log, not here. Open What is and is not recorded on the tab for the full list.
Ask the Audit Agent
Type a question into Ask the audit trail…, for example "Which admins changed the invoice exceptions agent's connections this month?" The agent answers from recorded events and cites each one. It knows which tab and filter you're looking at.
Ask for a chart and it draws one: bar, line or pie, grouped by action, status, channel, actor role, agent, subject type, author or day. Mindset computes the numbers, not the model.
The Audit Agent only reads. Its one exception is recording an attestation when you ask it to. Past conversations are kept in its history, and New conversation starts fresh.
There is no query builder on screen. You narrow the Record with the chips, and ask the agent for anything else. Query results and charts can't be downloaded.
Obligations and the evidence pack
Obligations maps the record to the controls a framework expects. Pick one under Framework, or leave All frameworks: EU AI Act, GDPR, SOC 2, NIST 800-53 AU, ISO 42001, HIPAA and SEC 17a-4.
Controls fall into three groups: Satisfied by the platform, Depends on your configuration and Requires a person to attest. For the last group, an admin clicks Attest, and the attestation is recorded with their name.
To export:
- Pick the Framework.
- Read what the pack will contain: the records in scope, sequence continuity and gaps, the chain integrity re-derived at generation time, provenance, the chain of custody and the control map.
- Click Generate pack.
You get one JSON file, named evidence-pack-<framework>-<date>.json. Each record in it carries who acted, what action, on what, through which channel, the outcome and when. It doesn't carry the record's payload. The export is itself recorded in the trail. The pack covers the whole trail for that framework. There's no date range to pick on screen.
Retention
Set it in Settings → Governance → Audit & data residency, as Audit retention (months). The minimum and the default is 6 months, and the maximum is 120.
When a record passes the retention period, Mindset removes the link between its placeholders and the real personal data, so they can no longer be resolved. The record itself is never deleted. A daily sweep does this, and records that it ran.
Conversation retention is a separate setting, in days, on the same tab. See What Mindset enforces for you.
What can go wrong
- Audit isn't in your rail. You aren't an org admin.
- The Posture card says records are "swept". The sweep removes identifying details. It doesn't delete records.
- You need records for one quarter only. The evidence pack has no date filter on screen. Generate it, then filter the JSON by
createdAt. - A widget, script or function edit isn't in the Record. Editing those writes no audit event.
- The pack isn't available. The deployment has no separate audit store configured, and the panel says The evidence pack is not available here.