Compliance & Audit
How does the platform support separation of duties between developers, operators, and auditors?
The platform offers role-based access controls that separate responsibilities: developers can author agent logic but not alter production records, operators manage infrastructure, and auditors receive read-only access to tamper-evident records, with payload visibility and access logs restricted per role. This ensures that no single role can create, deploy, and modify audit evidence, preventing unauthorized changes. However, effective separation also depends on proper identity provider integration and organizational policy enforcement, such as regular access reviews.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Compliance & Audit
What evidence artifacts should I gather from an AI agent platform for an audit of automated decision-making?
An AI agent platform provides verifiable step records and identity bindings as foundational audit evidence, though business rule correctness remains external.
- Compliance & Audit
How does the platform capture human-in-the-loop interventions for regulated workflows that require manual approval?
Durable execution suspends agents for human input, recording reviewer identity and decisions as signed steps for an unalterable compliance record.
- Compliance & Audit
Can I control where agent state and execution records are stored to comply with data residency requirements?
Region-specific deployment options ensure durable execution state and step payloads remain within geographic boundaries to meet localization mandates.