LensReading which lens this session carries.

Auditor evidence pack

Access request at manager approve exception

Information Technology · Identity & Access · line IT2A · Joiner Provisioning. This pack names every action taken on this unit, who or what took it, the authority that permitted it, and the model, prompt and policy versions in force at that moment.

Chain verified

Every record links to the one before it and hashes to its stored value. 5 records were re-hashed on this page load, in order, starting from the genesis value. Nothing was read from a cached verdict.

hash = sha256(prevHash + "|" + JSON{seq, unitRef, actor, action, outcome, occurredAt})

Records
5
Append-only, sequenced
Agent actions
4
Taken by software
Human actions
1
Taken by a named person
Refusals
0
Blocked by the authority register
Corrections
0
Later record supersedes an earlier one
Legal hold
None
Free to age out on schedule

The unit

What the work was, and where it sits

Reference
IT2A-1009
Subject
Beatriz Ellery
Requested by
Yuki Raman
Value
$66k
Materiality
medium
Currently held by
Entitlement Review Agent (agent)
Sub-function owner
Director, Identity & Access Management
Orchestrator
Identity Orchestrator

Every action, in order

Actor, authority, versions in force, and the hash link to the record before it

1
Joiner Provisioning AgentgbsCleared

Cleared receive trigger

2026-08-18 07:34:00ZAuthority IT2-AUTH-A1 · cap $250,000Jurisdiction UKAutonomy A4Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
ledger-write@t7, document-fetch@t9
in 50d890b3...d3111dout e04ed3ba...8dd80aartifact ART-IT2A-1001-1 genesis 6ed0c7b9...df3a94
2
Joiner Provisioning AgentgbsCleared

Cleared derive role

2026-08-18 07:51:00ZAuthority IT2-AUTH-A1 · cap $250,000Jurisdiction UKAutonomy A4Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
ledger-write@t7, document-fetch@t9
in 27582522...ae1a81out dd794ac2...3568e8artifact ART-IT2A-1001-2 6ed0c7b9...df3a94 0d028123...aff99f
3
Joiner Provisioning AgentgbsCleared

Cleared provision standard

2026-08-18 08:08:00ZAuthority IT2-AUTH-A1 · cap $250,000Jurisdiction UKAutonomy A4Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
ledger-write@t7, document-fetch@t9
in 3f6f2cce...f9c4fcout 65d634d2...b2b54dartifact ART-IT2A-1001-3 0d028123...aff99f 3b3395ad...20a44d
4
Joiner Provisioning AgentgbsCleared

Cleared duty check

2026-08-18 08:26:00ZAuthority IT2-AUTH-A1 · cap $250,000Jurisdiction UKAutonomy A4Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
ledger-write@t7, document-fetch@t9
in 5d60b500...acc61dout 21a06b7b...3fe986artifact ART-IT2A-1001-4 3b3395ad...20a44d 56a67be2...adbcb3
5
Director, Identity & Access Managementgate-approverIn progress

Holding at manager approve exception

2026-08-18 08:43:00ZAuthority IT2-AUTH-H1 · cap $250,000Jurisdiction UKAutonomy A0Retention TECH-3Y
Model
human@n-a
Prompt
human@n-a
Policy
segregation-of-duties@v4
Tools
none
in 8c1a19b8...b509c3out ff69c2b0...3ce461artifact ART-IT2A-1001-5 56a67be2...adbcb3 5e9b1bdc...f119c3

Authority relied on

Who was allowed to do this, up to what value, in which jurisdictions

IT2-AUTH-A1ActiveIdentity Orchestrator

Any unit on a identity & access line where every intake check passed, the policy in force is current, and the value sits inside the cap below.

Cap $2,000,000US · UK · DE · SGDelegated from Director, Identity & Access ManagementExpires 2027-01-17
IT2-AUTH-H1ActiveDirector, Identity & Access Management

Anything the agent grant refuses, plus any override of an agent outcome. An override must state what the agent concluded and why it is being set aside.

Cap $25,000,000US · UK · DE · SGDelegated from Information Technology leadershipExpires 2026-09-26

Versions in force

Exactly what was running when these actions were taken

KindIdentifierVersionStatusOwner
modelextract-lite2.9currentPlatform model council
policysegregation-of-dutiesv4currentInternal audit
prompttask-executionp21currentShared service engineering
toolsetledger-writet7currentFinance systems
toolsetdocument-fetcht9currentShared service engineering

Gates on this line

The control points this unit had to clear

Manager approve exception
Held for a named human when the unit exceeds the access request decision envelope, when confidence falls below the floor, or when a policy clause is engaged.
Approver: Director, Identity & Access Management · cleared on this chain

Records schedule and holds

How long this evidence must be kept, and whether it is frozen

TECH-3Y3 years
Technology change and access evidence
Security review and change audit requirement.
Deleted at three years from the change closing.

What this pack proves, and what it does not

Read this before you rely on it

It does prove
  • Every action carries a named actor, an actor kind, and a timestamp.
  • Every action names the authority grant that permitted it and the cap that grant carries.
  • Every action stamps the model, prompt, policy and tool versions in force at that moment.
  • Corrections are additive. A later record supersedes an earlier one and says why; the earlier record is never edited or deleted.
  • The chain is re-hashed live on this page, so a single altered field is detected immediately.
It does not prove
  • It is not tamper-proof against an attacker with write access to the store, who could rewrite the whole chain from genesis. Making that impossible requires publishing chain tips to a store this application cannot write to. That anchor is not built, and this page does not claim it.
  • The evidence in this demonstration is modeled from a simulated estate, not captured from production systems.
  • Identity here is the actor name recorded on the action. Cryptographic agent identity and signed attestation are a separate piece of work.