LensReading which lens this session carries.

Auditor evidence pack

Network change at post-mortem

Information Technology · Network · line IT5A · Network Incident. This pack names every action taken on this unit, who or what took it, the authority that permitted it, and the model, prompt and policy versions in force at that moment.

Chain verified

Every record links to the one before it and hashes to its stored value. 5 records were re-hashed on this page load, in order, starting from the genesis value. Nothing was read from a cached verdict.

hash = sha256(prevHash + "|" + JSON{seq, unitRef, actor, action, outcome, occurredAt})

Records
5
Append-only, sequenced
Agent actions
4
Taken by software
Human actions
1
Taken by a named person
Refusals
0
Blocked by the authority register
Corrections
0
Later record supersedes an earlier one
Legal hold
None
Free to age out on schedule

The unit

What the work was, and where it sits

Reference
IT5A-1016
Subject
Amara Haddad
Requested by
Farrah Mensah
Value
$56k
Materiality
medium
Currently held by
Segmentation Agent (agent)
Sub-function owner
Director, Network Services
Orchestrator
Network Orchestrator

Every action, in order

Actor, authority, versions in force, and the hash link to the record before it

1
Topology Monitoring AgentobserveCleared

Cleared correlate

2026-08-18 06:33:00ZAuthority IT5-AUTH-A1 · cap $250,000Jurisdiction AUAutonomy A3Retention TECH-3Y
Prompt
observe-scan@p11
Policy
segregation-of-duties@v4
Tools
read-only-lookup@t12
in a8eeeb94...543ebdout 45cf3a92...e78516artifact ART-IT5A-1002-1 genesis c55ed012...b6fbd0
2
Performance AgenttaskCleared

Cleared auto-remediate known

2026-08-18 07:02:00ZAuthority IT5-AUTH-A1 · cap $250,000Jurisdiction AUAutonomy A3Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
document-fetch@t9, read-only-lookup@t12
in 40f1d97f...28f76aout 6475bab1...a91146artifact ART-IT5A-1002-2 c55ed012...b6fbd0 5cb7360e...3f3036
3
Director, Network Servicesaccountable-ownerCleared

Cleared escalate

2026-08-18 07:32:00ZAuthority IT5-AUTH-H1 · cap $250,000Jurisdiction AUAutonomy A0Retention TECH-3Y
Model
human@n-a
Prompt
human@n-a
Policy
segregation-of-duties@v4
Tools
none
in b8a12908...f7c354out f6c1dbb5...e37218artifact ART-IT5A-1002-3 5cb7360e...3f3036 9cbe56ee...d5ee5c
4
Segmentation AgentpolicyCleared

Cleared restore

2026-08-18 08:01:00ZAuthority IT5-AUTH-A1 · cap $250,000Jurisdiction AUAutonomy A2Retention TECH-3Y
Prompt
gate-approval@p8
Policy
segregation-of-duties@v4
Tools
read-only-lookup@t12
in 2ad25100...78f75dout 8f0f0f7e...633c5bartifact ART-IT5A-1002-4 9cbe56ee...d5ee5c 25ccad54...ec2fd3
5
Network Policy AgentpolicyIn progress

Holding at post-mortem

2026-08-18 08:31:00ZAuthority IT5-AUTH-A1 · cap $250,000Jurisdiction AUAutonomy A2Retention TECH-3Y
Prompt
gate-approval@p8
Policy
segregation-of-duties@v4
Tools
read-only-lookup@t12
in ceee60fb...cd7d89out 3c6861de...d5faa7artifact ART-IT5A-1002-5 25ccad54...ec2fd3 f94d8bc9...1460db

Authority relied on

Who was allowed to do this, up to what value, in which jurisdictions

IT5-AUTH-A1ActiveNetwork Orchestrator

Any unit on a network line where every intake check passed, the policy in force is current, and the value sits inside the cap below.

Cap $250,000US · UK · DE · SG · AUDelegated from Director, Network ServicesExpires 2027-06-09
IT5-AUTH-H1ActiveDirector, Network Services

Anything the agent grant refuses, plus any override of an agent outcome. An override must state what the agent concluded and why it is being set aside.

Cap $2,000,000US · UK · DE · SG · AUDelegated from Information Technology leadershipExpires 2027-06-13

Versions in force

Exactly what was running when these actions were taken

KindIdentifierVersionStatusOwner
modelreasoner-core5.4currentPlatform model council
modelextract-lite2.9currentPlatform model council
modelobserve-signal3.1currentSensing guild
policysegregation-of-dutiesv4currentInternal audit
promptgate-approvalp8currentGovernance office
prompttask-executionp21currentShared service engineering
promptobserve-scanp11currentSensing guild
toolsetread-only-lookupt12currentPlatform engineering
toolsetdocument-fetcht9currentShared service engineering

Gates on this line

The control points this unit had to clear

Escalate
Held for a named human when the unit exceeds the network change decision envelope, when confidence falls below the floor, or when a policy clause is engaged.
Approver: Director, Network Services · not reached

Records schedule and holds

How long this evidence must be kept, and whether it is frozen

TECH-3Y3 years
Technology change and access evidence
Security review and change audit requirement.
Deleted at three years from the change closing.

What this pack proves, and what it does not

Read this before you rely on it

It does prove
  • Every action carries a named actor, an actor kind, and a timestamp.
  • Every action names the authority grant that permitted it and the cap that grant carries.
  • Every action stamps the model, prompt, policy and tool versions in force at that moment.
  • Corrections are additive. A later record supersedes an earlier one and says why; the earlier record is never edited or deleted.
  • The chain is re-hashed live on this page, so a single altered field is detected immediately.
It does not prove
  • It is not tamper-proof against an attacker with write access to the store, who could rewrite the whole chain from genesis. Making that impossible requires publishing chain tips to a store this application cannot write to. That anchor is not built, and this page does not claim it.
  • The evidence in this demonstration is modeled from a simulated estate, not captured from production systems.
  • Identity here is the actor name recorded on the action. Cryptographic agent identity and signed attestation are a separate piece of work.