Actor
Who or what acted?
Assure Evidence and control for AI agents
Assure shows what AI agents did, whether they were authorized to do it, and what evidence supports that conclusion.
Keep your logs. Assure connects them into evidence you can investigate, test and independently verify.
01 / The problem
When something goes wrong, a log line may not answer the question that matters:
“What actually happened?”02 / The shift
Keep your logs. Assure does not replace them. It connects events to actors, exact versions, authority and outcomes.
10:21 document.updated
10:24 approval.completed
10:26 document.sentLogs are events.
Evidence is context.
There was an approval. There was a send. But the approved document was not the document that left the system.
03 / Evidence model
Who or what acted?
What was it allowed to do?
What exact thing changed?
Who approved which version?
What actually happened?
What happened next?
04 / How it works
Assure Core remains deterministic and evidence-first. It warns and evaluates; it does not autonomously block customer systems.
Collect the minimum required evidence.
Link related actions, artifacts and approvals.
Run deterministic business-control checks.
Surface evidence-backed exceptions.
Replay what happened later.
Produce a scoped evidence package.
05 / Flagship workflow
Demo / SyntheticNo real customer data. No protected form content. A synthetic real-estate transaction workflow makes the control visible in under five minutes.
AI creates APS v7Version commitment recorded
Broker approves APS v7Approval bound to the exact hash
AI changes closing dateSystem creates APS v8
APS v8 is sentExternal delivery observed
Assure does not decide whether the contract is legally correct. It answers a narrower question: Was the document sent the document an authorized person approved?
06 / Authority
Assure records which mandate applied when the action happened.
It records and evaluates authority evidence. It does not claim to enforce the boundary unless a separate application gate actually does.
07 / Controls
Results are evidence states, not optimism. Missing evidence displays as UNKNOWN—never as a pass.
Every externally sent agreement has an approval for the exact sent version.
EXCEPTIONNo material edit after approval without new approval.
EXCEPTIONEvery agent action maps to a valid principal and mandate.
PASSEvery external delivery can be reconstructed.
PASSCustomer A evidence never appears in Customer B's tenant.
PASSUnderlying private content was independently verified.
UNKNOWN08 / Replay
Assure reconstructs observable evidence. It does not claim access to hidden model chain-of-thought.
09 / Optional intelligence
Assure Core works without these systems. Their outputs are not automatically fact.
Have we seen this before? What changed? Was it fixed?
What hypotheses explain this finding? What test could falsify them?
Which investigation is worth running first?
Is behaviour changing in a way that deserves attention?
10 / Open Agent Observatory
We study public metadata and controlled, synthetic runtime behaviour. We do not observe project users, and project maintainers do not endorse Assure.
Registered projects and harnesses at exact public pins.
Recurring, synthetic, network-bounded runtime evidence.
No real-model claim. Deterministic local adapters only.
11 / Regulatory direction
Across jurisdictions, AI governance is moving toward stronger accountability, documentation, testing, monitoring and human oversight. Applicability depends on role, system and context.
Canadian privacy regulators emphasize appropriate purposes, safeguards, transparency, accountability, traceability and human review. Canada does not have one universal private-sector AI-agent statute.
Privacy commissioners · 2023 ↗Enforcement and selected transparency and GPAI duties apply in 2026; specified high-risk obligations apply later. Not every AI agent is a high-risk system.
European Commission · updated 2026 ↗No single general federal equivalent to the EU AI Act. Federal activity, sector obligations, state laws and voluntary frameworks—including NIST AI RMF—coexist.
Congressional Research Service · 2025 ↗OSFI E-23 applies to federally regulated financial institutions, not automatically to every software vendor. Vendors may still face downstream evidence and diligence demands.
OSFI · effective 2027 ↗Educational information only. Assure does not provide legal advice or guarantee compliance.
12 / Assurance market
The world's largest assurance firms publicly describe work in AI governance, risk, controls, testing, documentation and assurance.
13 / Frameworks
Descriptive risk and governance themes; no certification claim.
Evidence can support selected management-system activities; no certification coverage.
Control, sampling, workpaper and retest concepts only; no SOC report.
Capability matrix records the tested OSCAL adapter as missing.
Primary references: NIST AI RMF · ISO/IEC 42001 · NIST OSCAL
14 / Privacy and deployment
Record the minimum evidence needed for a control or reconstruction.
Bind versions without claiming a hash proves content is correct.
Reduce exposure while recognizing tokenized values may still be personal data.
Keep content under customer control where the deployment supports it.
15 / Review
Assure can prepare structured evidence. Independent assurance remains independent.
Accountability, appropriate purposes, safeguards, transparency, traceability and human review under applicable Canadian privacy law.
The Act applies progressively; enforcement and selected transparency/GPAI duties apply in 2026, with specified high-risk-system dates later.
No broad federal AI regulatory authority had been enacted; U.S. activity remained a mix of targeted federal provisions, agency authority, voluntary measures and state laws.
The AI RMF is a voluntary framework for incorporating trustworthiness considerations into AI design, development, use and evaluation.
Federally regulated financial institutions are expected to apply risk-based, lifecycle-wide model governance, inventory, review, approval and monitoring; effective 2027-05-01.
Requirements for establishing, implementing, maintaining and continually improving an AI management system.
OSCAL is a machine-readable control and assessment model. Assure's adapter remains not yet mapped and makes no compatibility claim.
Public AI-assurance services covering governance, controls, monitoring, testing and evidence-based review.
Public AI controls and assurance services spanning governance, risk, controls, testing and reporting.
EY describes AI assurance work around governance, model objectives, training/validation procedures, data reliability and management controls.
Public AI-assurance services covering risk assessment, control testing, model validation, evidence and reporting.
Start with one workflow
We'll show you what can be recorded, reconstructed and tested.