Audit Trail — KYA Glossary

An audit trail is the record of what an agent did, on whose authority, and when — enough to reconstruct decisions and attribute them.

Why it matters

Accountability needs evidence. Without an audit trail you cannot answer “which agent, authorised by whom, did this?” after the fact — and you cannot investigate an incident, prove compliance, or improve policy. It is the evidence layer of the accountability that KYA extends beyond KYC and KYB.

It builds on established logging and governance practice:

  • Log management (NIST SP 800-92) defines how to collect, protect, and analyse security logs; an agent audit trail is a specialised, identity-rich log.
  • EU AI Act Article 12 requires high-risk AI systems to technically allow automatic recording of events (logs) over the system’s lifetime — a regulatory floor for record-keeping.
  • AI risk frameworks (NIST AI RMF) and management systems (ISO/IEC 42001) place accountability and monitoring in governance structures, which log evidence supports.

What an agent audit record should capture

  • The agent’s verifiable identity and its principal.
  • The authority or mandate under which it acted.
  • The action, target, and parameters (including amount, where relevant).
  • Timestamp, outcome, and any human approval or step-up.
  • A tamper-evident link so records cannot be silently altered.

Caution

Logging agent inputs and outputs can capture sensitive personal data. Apply data-minimisation and retention rules, and keep secrets out of logs.

How it works in practice

An agent audit record is an identity-rich log line: it joins the action to the agent identity and to the delegation that authorised it, so the record is meaningful on its own. That is what lets an investigator reconstruct a decision after the fact and attribute it to a principal through the agent.

Two properties do most of the work: completeness (enough fields to answer who, what and why) and integrity (evidence the record was not altered afterwards). NIST SP 800-92 covers collecting and protecting logs; the EU AI Act adds an automatic-logging duty for high-risk systems. For where the record fits in the verification sequence, see the verification guide, and for logging code see the examples.

Related terms

Sources

  1. NIST, SP 800-92, Guide to Computer Security Log Management (accessed 2026-10-03)
  2. European Commission, EU AI Act, Article 12 — Record-keeping (accessed 2026-10-03)
  3. NIST, AI 100-1, AI RMF 1.0 (accessed 2026-10-03)
  4. ISO, ISO/IEC 42001:2023 (accessed 2026-10-03)

Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.