01

Governance must exist before the incident

Policies describe what should happen. An incident review must prove what actually happened: who asked, which scope was active, what knowledge was retrieved, which model responded, what tools were called and whether a person approved the consequence.

If those facts are assembled from separate systems after the event, the organisation begins its investigation with gaps. Reconstruction is therefore a platform capability, not a reporting feature.

The audit trail is the memory of the control system.

02

What a complete AI event should contain

A useful event is more than a timestamp and user name. It connects the request to the decision path so risk, technology and business owners can review the same evidence.

  • Human or agent identity and the active Personal, Teamspace or Organisation scope.
  • Requested operation, retrieved sources and any policy that allowed or denied access.
  • Selected model, routing reason, tokens, latency and cost.
  • Tool calls, generated artefacts and destination systems.
  • Approval request, named reviewer, decision, time and comments.
  • A tamper-evident relationship to the preceding and following events.
03

Denied activity is evidence too

A blocked retrieval proves that a boundary was enforced. A rejected approval proves that consequential action remained under human authority. Both should be searchable and exportable alongside successful activity.

Without denied events, dashboards reward volume while hiding the controls that made the system safe. Mature governance measures prevented actions as carefully as completed ones.

04

Build the incident timeline in minutes

An investigator should be able to filter by user, agent, scope, model, workflow or artefact and move from a business outcome back to the original source passages. The timeline should show where automation stopped, who intervened and what happened next.

This shortens the distance between detection and explanation. It also lets the organisation improve policies using actual behaviour rather than assumptions.

  • Start with the affected answer, document or action.
  • Trace back through the workflow and every tool call.
  • Confirm the active scope and retrieved passages.
  • Review model selection and policy evaluation.
  • Verify the human decision before any external consequence.
05

Make evidence part of the operating model

Audit evidence should support routine operations, not only investigations. Teams can review cost anomalies, recurring denials, approval bottlenecks and agent behaviour before they become incidents.

The goal is not surveillance. It is accountable autonomy: people and agents can move faster because the organisation can see, control and explain the work.

Scale autonomy only as quickly as you can preserve attribution, approval and proof.