Kanonik

Help center

An audit trail that survives scrutiny.

Inputs and outputs are a receipt. Buyers now ask for the full decision chain.

Ask most teams for their AI audit trail and you get inputs and outputs: the prompt went in, the result came out. That is a receipt, and when an auditor, a regulator, or opposing counsel asks how a decision was actually made, a receipt ends the conversation in the wrong place.

The standard that enterprise buyers are starting to put in their questionnaires is different. For any system that acts on its own, they want logging of every action: what the system considered, which tools it called, what data it accessed, and why it chose the path it did. The full chain, not the endpoints.

What "survives scrutiny" actually requires

Four properties separate a defensible record from a receipt:

  • Completeness. The whole decision chain is captured, not just the final answer. The proposal, the candidates that were weighed, the rule that was applied, the verdict, and the reasoning behind it.
  • Tamper-evidence. The record cannot be quietly edited after the fact. If a single entry changed, it would be detectable. Without this, the trail proves nothing, because anyone could have rewritten it.
  • Attribution. Each change names the human who approved it and when. "An AI suggested it" is where a defense falls apart; "this named person approved it at this time, with this reasoning on the record" is where it holds.
  • Independent verification. The record shows not just that a control is documented, but that what the system did was checked against that control before it took effect, by something the system itself cannot bypass.

How Kanonik produces it

Every change an AI proposes is recorded as a structured entry: the proposal, what was considered, the rule that was checked, the verdict, and the reasoning. That entry is appended to a permanent record where each entry is chained to the one before it, so any later tampering is detectable. The change does not take effect until a named human approves it, and that approval is part of the record. You can export the whole thing, with its integrity proof, in one action.

The point is not more logging. It is a record built to answer the question that ends most audit conversations: not "what did the AI output," but "what did it do, why, and who stood behind it." That question is the one the new agent-governance expectations are converging on, and it is the one this record is built to answer.

To see what the sealed package your auditor receives looks like, read Exporting your evidence for an audit.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email support@kanonik.ai and a person who works on the product answers.