The compliance record for AI agents

Your AI acts.
You keep
the proof.

Auditant records what an agent attempted, which rule decided, who approved it and what happened next — then seals the record so an auditor can check it without trusting you, or us. For the person who signs; connected by the person who ships, in two lines.

Our own record: 915 actions, sealed through #914, 71 of 73 seals countersigned by an independent clock. See it

Priced per agent, never per event. Free for one agent. Only fingerprints leave your environment — never the contents.

Auditant / decision receiptsample · 09:12:06Z

Wire transfer held for human approval.

Agent
payments-bot
Action
Wire transfer, $50,000
Rule
Above $10,000, a named person signs first
Decision
Held for approval
Reason
$50,000 is above the $10,000 threshold
Receipt
rcpt_fb78d8d7…f2654
Key
auditant-ae8f48708c44
sha256 · signed

A real receipt, issued by Auditant on a sample record. Anyone can verify it offline with the published key.

Records fromOpenAIAnthropicLangChainLiteLLMLiteLLMVapiOpenTelemetryAmazon S3
How it works

Watch first. Draw the lines. Hand over the proof.

A staged rollout that earns the right to enforce before it interrupts production.

  1. 01Day one

    Connect in watch-only mode

    Use the SDK, your gateway, or the OpenTelemetry pipeline you already run. The record starts; nothing is blocked.

  2. 02First week

    See what actually happened

    Model calls, tool calls, cost, people and resulting effects land in one ordered record, with coverage gaps stated separately.

  3. 03When ready

    Draw the lines

    Write limits in plain English. Every rule starts by observing, then holds or refuses only after you arm it.

  4. 04When asked

    Hand over the proof

    Export one evidence bundle or examiner packet. The reviewer verifies it offline without an Auditant account.

Works with

Your stack stays your stack.

Native instrumentors where they exist; open protocols and explicit event APIs everywhere else. The connection path is stated on every group.

  • Models

    OpenAI, Anthropic, Gemini, any tool-calling LLM

    Automatic for the named SDKs; every other provider connects through OpenTelemetry, LiteLLM, or the event API.

  • Orchestration

    LangChain, LangGraph, CrewAI, LlamaIndex, OpenAI Agents SDK, your own loop

    Framework spans are captured automatically when installed; a custom loop uses record() and decide().

  • Voice

    Retell, Vapi, any audio loop

    Vapi connects directly. Retell and other call stacks use a verified webhook relay or the canonical voice ingest API.

  • Tools

    MCP servers, REST, Python & TypeScript SDKs, internal services

    Record the attempted call at the agent, then join it to the effect your service or gateway reports.

  • Gateways & telemetry

    LiteLLM, OpenTelemetry, Vercel AI SDK, any OTLP collector

    Keep the pipeline you already run; Auditant maps its spans into the same evidence format.

  • Evidence destinations

    Amazon S3 Object Lock, JSON bundles, examiner packets, SIEM webhooks

    The record leaves as portable evidence, not a screenshot that only works inside our account.

One session, exactly as the record holds it.

A $50,000 payout: recorded, held, approved by name, executed, sealed. Every block carries the fingerprint of the one before it, so nothing can be quietly changed later.

001

The session opens under a name.

Which agent acted, in which session, on whose behalf. Without that last part there is no per-customer answer, complaint or erasure later.

001 · Session3b0c…9e1a
Session opened
payments-bot, on behalf of customer 8841
002

The model call, as a fingerprint.

A fingerprint of what went in and what came out, the model, and the price. The prompt itself never leaves your environment.

002 · Model call91ab…c07d
Model call
Fingerprints of the prompt and the answer · 1,204 tokens · $0.0091
004

The rule runs first. The wire waits.

“Moving more than the threshold requires a named human to approve first.” Synchronous, on the request path — the side effect has not happened. A signed receipt is issued for the decision itself.

004 · Rule10e5957e
Wire transfer held
Rule: moving more than $10,000 needs a named person. Amount: $50,000.
005

A person answers, and the answer is a row.

Taken from her authenticated server session, not a service account — the field every investigation ends on.

005 · Approvalea342c48
Approved by priya@lender.io
From her own signed-in session — “verified against the signed payout schedule”
006

Only now does the money move.

The effect plane confirms it landed — the ledger entry, not the agent's claim that it made one.

006 · Action11f0545e
Wire transfer, $50,000
Executed. The bank's own ledger entry confirms it landed.
Seal #26

Sealed. Countersigned by a clock that is not ours.

A checkpoint signs the chain head with our key, an RFC 3161 timestamp authority countersigns it, and a copy is held in write-once storage. From here, changing any earlier row is a computable fact.

#26 · Seal9ac7455f
Signed by Auditant, countersigned at 09:14:02Z
Covers every row through 007. A copy is held in write-once storage that nobody — including us — can delete.
The console

The decision and its proof, in one place.

Start with what needs attention. Open the action to see the rule, the evidence and the accountable human response, then follow the same record through activity, coverage and export.

Product tour · sample recordCaptured from the live demo
The Auditant console
A real capture of the console on a sample record. Open the full dashboard, no account →Held → approved by a named person → executed

Four questions, answered for both readers.

Two people come to this page — the one who signs and the one who ships. The same answers, side by side.

What is recorded

Every action your agents take — what they read, what they decided, who approved, what actually happened — written as it happens, in an order nobody can quietly rearrange.

What is recorded

Model calls, tool calls, rule decisions, human approvals and the effects that landed, in one format. Each event carries a fingerprint of the previous one, on a store that only appends.

What can be stopped

Anything you name in plain English. Above a threshold, a person you name has to say yes first, and their yes is on the record under their name.

What can be stopped

One synchronous check before the action runs: allow, refuse, change, hold or defer. Every rule starts in watch-only mode. A halt switch beats every rule and is itself recorded.

What leaves your environment

Fingerprints, not contents. We can prove nothing was altered without ever seeing a prompt, a document or a customer's data.

What leaves your environment

By default: who, what, when, the outcome, and a fingerprint of every input and output. Optionally the contents go to your own storage bucket. Never health or card data.

Why an auditor believes it

Sealed by us, countersigned by an independent clock, and checkable by the auditor on their own laptop — without asking us anything.

Why an auditor believes it

Signed seals, an independent timestamp on each, and an optional write-once copy. One command — auditant verify — recomputes every fingerprint and names the first row that no longer matches.

Don't take our word for it.

Four rows of a real sample record. Change one; the verifier tells you exactly where the record stopped being true. The real verifier runs on your own machine — one command.

Try the verifier

Change one fact. Break the chain.

Untouched, the record verifies. Change what row 006 says happened and that row — and every row after it — stops matching the seal.

The sample record · four rowssample
004
Rulewire transfer held for a person
10e5957e
005
Approvalapproved by priya@lender.io
ea342c48
006
Actionwire transfer · $50,000 · executed
11f0545e
007
Sessionsession closed
9ac7455f
✓ VERIFIED — chain intact, checkpoints signedAnchored through sequence 7 (8 events), signature onlyIntegrity is proven. Coverage — whether every action reached the record — is a deployment question, answered separately.
Questions, answered plainly

The short version first.

Open only what you need. The product details stay available to readers and search engines without turning the page into a wall of copy.

01

What is an AI agent audit trail?

It is a chronological record of an agent’s model calls, tool calls, policy decisions, human approvals and resulting actions. Auditant links those events into one tamper-evident chain so an examiner can follow a decision from intent to outcome.

02

Does Auditant only record actions, or can it stop them?

Both. Auditant records every observed action and can evaluate policy before a tool runs. A rule can allow the action, refuse it, or hold it until an authenticated human approves or rejects it.

03

What does tamper-evident verification actually prove?

Verification proves that the records Auditant received have not been altered after they were sealed. It does not prove that every action reached the record; deployment coverage is measured and reported separately.

04

Do prompts and customer data have to leave our environment?

No. The default record stores metadata and cryptographic hashes rather than prompt or response payloads. You can prove integrity while keeping sensitive content in storage you control.

05

Which agent frameworks and model providers work with Auditant?

OpenAI, Anthropic and Gemini model calls can be auto-instrumented. LangChain, LangGraph, CrewAI, LlamaIndex and the OpenAI Agents SDK connect through their framework instrumentation; any other tool-calling model or custom loop can emit the same evidence through OpenTelemetry, LiteLLM, the Python or TypeScript SDK, or the event API.

06

How is Auditant priced?

Pricing is per agent, never per recorded event. One agent is free to evaluate, and paid bands include unlimited recorded actions so cost never rewards incomplete coverage.