Assure Evidence and control for AI agents

Know what your AI did. Prove it.

Assure shows what AI agents did, whether they were authorized to do it, and what evidence supports that conclusion.

Keep your logs. Assure connects them into evidence you can investigate, test and independently verify.

01 / The problem

AI agents don't just answer.
They act.

Edit filesCall toolsGenerate documentsChange recordsSend messagesMake recommendationsTrigger workflows

When something goes wrong, a log line may not answer the question that matters:

“What actually happened?”

02 / The shift

Logs show activity.
Assure shows evidence.

Keep your logs. Assure does not replace them. It connects events to actors, exact versions, authority and outcomes.

Raw logs
10:21 document.updated
10:24 approval.completed
10:26 document.sent
Assure
  1. 10:21 Purchase Agreement v3 created
  2. 10:24 Human approved Purchase Agreement v3
  3. 10:25 AI created Purchase Agreement v4
  4. 10:26 Purchase Agreement v4 sent
FindingSent artifact did not match approved artifact.

There was an approval. There was a send. But the approved document was not the document that left the system.

03 / Evidence model

Six questions.
One connected record.

01

Actor

Who or what acted?

02

Mandate

What was it allowed to do?

03

Artifact

What exact thing changed?

04

Approval

Who approved which version?

05

Action

What actually happened?

06

Outcome

What happened next?

04 / How it works

From event trail
to reviewable evidence.

Assure Core remains deterministic and evidence-first. It warns and evaluates; it does not autonomously block customer systems.

  1. 01Record

    Collect the minimum required evidence.

  2. 02Connect

    Link related actions, artifacts and approvals.

  3. 03Test

    Run deterministic business-control checks.

  4. 04Warn

    Surface evidence-backed exceptions.

  5. 05Reconstruct

    Replay what happened later.

  6. 06Export

    Produce a scoped evidence package.

05 / Flagship workflow

Demo / Synthetic

An AI agent
prepares an offer.

No real customer data. No protected form content. A synthetic real-estate transaction workflow makes the control visible in under five minutes.

01Transaction data
02Forms
03Conditions
04Document
05Human approval
06External delivery
Transaction #A-4821Synthetic evidence stream

AI creates APS v7Version commitment recorded

Broker approves APS v7Approval bound to the exact hash

AI changes closing dateSystem creates APS v8

APS v8 is sentExternal delivery observed

Approval mismatchExternal artifact did not match the approved version.

Assure does not decide whether the contract is legally correct. It answers a narrower question: Was the document sent the document an authorized person approved?

Enforce is disabled.Assure warns and evaluates. The application itself may require human approval.

06 / Authority

AI agents need
a mandate.

Assure records which mandate applied when the action happened.

It records and evaluates authority evidence. It does not claim to enforce the boundary unless a separate application gate actually does.

Allowed
  • Read transaction data
  • Draft paperwork
  • Calculate dates
  • Request approval
Not authorized
  • Sign for a client
  • Waive a condition
  • Transfer funds
  • Change price after approval
  • Send a binding artifact without required approval

07 / Controls

Test the business control.
Not just the software.

Results are evidence states, not optimism. Missing evidence displays as UNKNOWN—never as a pass.

Every externally sent agreement has an approval for the exact sent version.

EXCEPTION

No material edit after approval without new approval.

EXCEPTION

Every agent action maps to a valid principal and mandate.

PASS

Every external delivery can be reconstructed.

PASS

Customer A evidence never appears in Customer B's tenant.

PASS

Underlying private content was independently verified.

UNKNOWN

08 / Replay

When someone asks “Why did this happen?”
start with evidence.

01Source event
02Document version
03Agent action
04Approval
05External action
06Outcome

Assure reconstructs observable evidence. It does not claim access to hidden model chain-of-thought.

09 / Optional intelligence

Evidence first.
Intelligence second.

Assure Core works without these systems. Their outputs are not automatically fact.

Brain

Institutional memory.

Have we seen this before? What changed? Was it fixed?

AION

Investigation.

What hypotheses explain this finding? What test could falsify them?

AOK

Prioritization.

Which investigation is worth running first?

Sentinel

Warnings.

Is behaviour changing in a way that deserves attention?

Current boundaryBrain, AION and AOK remain governed optional layers. Sentinel is experimental, uncalibrated and Observe/Warn only. No block or intervention claim.

10 / Open Agent Observatory

Tested against real
open-source agent systems.

We study public metadata and controlled, synthetic runtime behaviour. We do not observe project users, and project maintainers do not endorse Assure.

10/10Public metadata monitoring

Registered projects and harnesses at exact public pins.

10/10Controlled runtime testing

Recurring, synthetic, network-bounded runtime evidence.

0/10Real-model testing

No real-model claim. Deterministic local adapters only.

Open the public observatory ↗

11 / Regulatory direction

The direction
is clear.

Across jurisdictions, AI governance is moving toward stronger accountability, documentation, testing, monitoring and human oversight. Applicability depends on role, system and context.

Canada

Accountability under existing privacy law.

Canadian privacy regulators emphasize appropriate purposes, safeguards, transparency, accountability, traceability and human review. Canada does not have one universal private-sector AI-agent statute.

Privacy commissioners · 2023 ↗
European Union

Risk-based rules, phased over time.

Enforcement and selected transparency and GPAI duties apply in 2026; specified high-risk obligations apply later. Not every AI agent is a high-risk system.

European Commission · updated 2026 ↗
United States

A targeted and sectoral landscape.

No single general federal equivalent to the EU AI Act. Federal activity, sector obligations, state laws and voluntary frameworks—including NIST AI RMF—coexist.

Congressional Research Service · 2025 ↗
Canadian financial services

Lifecycle model-risk expectations.

OSFI E-23 applies to federally regulated financial institutions, not automatically to every software vendor. Vendors may still face downstream evidence and diligence demands.

OSFI · effective 2027 ↗

13 / Frameworks

Map evidence to the frameworks
your organization uses.

NIST AI RMFMapped

Descriptive risk and governance themes; no certification claim.

ISO/IEC 42001Partial

Evidence can support selected management-system activities; no certification coverage.

SOC-type assurance conceptsPartial

Control, sampling, workpaper and retest concepts only; no SOC report.

OSCAL exportNot yet mapped

Capability matrix records the tested OSCAL adapter as missing.

Primary references: NIST AI RMF · ISO/IEC 42001 · NIST OSCAL

14 / Privacy and deployment

You shouldn't have to centralize
every prompt and document.

01

Metadata-first evidence

Record the minimum evidence needed for a control or reconstruction.

02

Hash and reference binding

Bind versions without claiming a hash proves content is correct.

03

Redaction and tokenization

Reduce exposure while recognizing tokenized values may still be personal data.

04

Customer-controlled artifacts

Keep content under customer control where the deployment supports it.

Deployment boundaryPrivate-edge and BYOC references are implemented and CI-evidenced, not claimed as active customer deployments. Some controls require authorized access to underlying content.

15 / Review

Give reviewers evidence.
Not screenshots.

Assure can prepare structured evidence. Independent assurance remains independent.

Scoped evidence packageReviewable · Exportable · Verifiable
01actors02agents03versions04mandates05artifacts06approvals07actions08exceptions09control results10remediation11retest
Source manifest Reviewed 2026-09-16
European Union

The enforcement framework of the AI Act

The Act applies progressively; enforcement and selected transparency/GPAI duties apply in 2026, with specified high-risk-system dates later.

Publisher
European Commission, Directorate-General CONNECT
Published
2026-08-24
Last reviewed
2026-09-16
https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act ↗
United States

Regulating Artificial Intelligence: U.S. and International Approaches and Considerations for Congress

No broad federal AI regulatory authority had been enacted; U.S. activity remained a mix of targeted federal provisions, agency authority, voluntary measures and state laws.

Publisher
Congressional Research Service
Published
2025-06-04
Last reviewed
2026-09-16
https://www.congress.gov/crs_external_products/R/PDF/R48555/R48555.2.pdf ↗
United States

Artificial Intelligence Risk Management Framework 1.0

The AI RMF is a voluntary framework for incorporating trustworthiness considerations into AI design, development, use and evaluation.

Publisher
U.S. National Institute of Standards and Technology
Published
2023-01-26
Last reviewed
2026-09-16
https://www.nist.gov/itl/ai-risk-management-framework ↗
International

ISO/IEC 42001:2023 — Artificial intelligence management system

Requirements for establishing, implementing, maintaining and continually improving an AI management system.

Publisher
International Organization for Standardization
Published
2023-12-18
Last reviewed
2026-09-16
https://www.iso.org/standard/81230.html ↗
United States

OSCAL releases and compatibility commitment

OSCAL is a machine-readable control and assessment model. Assure's adapter remains not yet mapped and makes no compatibility claim.

Publisher
U.S. National Institute of Standards and Technology
Published
2023-11-08
Last reviewed
2026-09-16
https://pages.nist.gov/OSCAL/resources/downloads/ ↗

Start with one workflow

Bring us one
AI workflow.

We'll show you what can be recorded, reconstructed and tested.

Assure Core · Evidence and controlEnforce disabledNo compliance claim© 2026 One Lab