Compliance & Audit
How can I verify that the agent's runtime permissions were enforced and no unauthorized data access occurred?
Catalyst embeds the effective permission set used for each step into the signed step record, including the data scope and identity claims. Auditors can compare these recorded permissions against the intended policy to spot unauthorized access. This audit depends on policy correctness and cannot catch privilege escalations outside recorded steps; it provides evidence, not prevention.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Compliance & Audit
What evidence artifacts should I gather from an AI agent platform for an audit of automated decision-making?
An AI agent platform provides verifiable step records and identity bindings as foundational audit evidence, though business rule correctness remains external.
- Compliance & Audit
How does the platform capture human-in-the-loop interventions for regulated workflows that require manual approval?
Durable execution suspends agents for human input, recording reviewer identity and decisions as signed steps for an unalterable compliance record.
- Compliance & Audit
Can I control where agent state and execution records are stored to comply with data residency requirements?
Region-specific deployment options ensure durable execution state and step payloads remain within geographic boundaries to meet localization mandates.