LensReading which lens this session carries.

Auditor evidence pack

Alert at contain in-policy

Information Technology · Cybersecurity Operations · line IT7A · Security Alert Triage. This pack names every action taken on this unit, who or what took it, the authority that permitted it, and the model, prompt and policy versions in force at that moment.

Chain verified

Every record links to the one before it and hashes to its stored value. 5 records were re-hashed on this page load, in order, starting from the genesis value. Nothing was read from a cached verdict.

hash = sha256(prevHash + "|" + JSON{seq, unitRef, actor, action, outcome, occurredAt})

Records
5
Append-only, sequenced
Agent actions
5
Taken by software
Human actions
0
Taken by a named person
Refusals
0
Blocked by the authority register
Corrections
0
Later record supersedes an earlier one
Legal hold
None
Free to age out on schedule

The unit

What the work was, and where it sits

Reference
IT7A-1011
Subject
Amara Novak
Requested by
Bruno Muller
Value
$81k
Materiality
medium
Currently held by
AI-OPS spine (gbs)
Sub-function owner
Director, Security Operations
Orchestrator
Security Operations Orchestrator

Every action, in order

Actor, authority, versions in force, and the hash link to the record before it

1
Security Operations OrchestratororchestratorCleared

Cleared ingest

2026-08-18 08:10:00ZAuthority IT7-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A3Retention TECH-3Y
Prompt
orchestrator-brief@p14
Policy
segregation-of-duties@v4
Tools
read-only-lookup@t12, notify-and-route@t5
in 5efbca04...748353out 241e5f66...8b3b47artifact ART-IT7A-1001-1 genesis 9ea94235...fb5f5d
2
Alert Triage AgenttaskCleared

Cleared enrich

2026-08-18 08:20:00ZAuthority IT7-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A3Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
document-fetch@t9, read-only-lookup@t12
in 626ef2e9...6458c0out 5b5cdf85...4098fdartifact ART-IT7A-1001-2 9ea94235...fb5f5d ca4efcf5...33cb12
3
Threat Intelligence AgenttaskCleared

Cleared score

2026-08-18 08:30:00ZAuthority IT7-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A3Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
document-fetch@t9, read-only-lookup@t12
in 4b8b17b7...8ca04fout ddf96781...d1fbddartifact ART-IT7A-1001-3 ca4efcf5...33cb12 10c22aed...85cd62
4
Containment AgenttaskCleared

Cleared auto-close false positive

2026-08-18 08:40:00ZAuthority IT7-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A3Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
document-fetch@t9, read-only-lookup@t12
in 3d954330...12e33aout 3507d8eb...74fb25artifact ART-IT7A-1001-4 10c22aed...85cd62 d8d94f64...024098
5
Forensics Support AgenttaskIn progress

Holding at contain in-policy

2026-08-18 08:50:00ZAuthority IT7-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A3Retention TECH-3Y
Prompt
task-execution@p21
Policy
segregation-of-duties@v4
Tools
document-fetch@t9, read-only-lookup@t12
in 6d0503ce...e11baeout f92ff098...b04a68artifact ART-IT7A-1001-5 d8d94f64...024098 83e21132...deb6eb

Authority relied on

Who was allowed to do this, up to what value, in which jurisdictions

IT7-AUTH-A1ActiveSecurity Operations Orchestrator

Any unit on a cybersecurity operations line where every intake check passed, the policy in force is current, and the value sits inside the cap below.

Cap $2,000,000US · UK · DE · SG · AU · FRDelegated from Director, Security OperationsExpires 2026-11-15

Versions in force

Exactly what was running when these actions were taken

KindIdentifierVersionStatusOwner
modelreasoner-core5.4currentPlatform model council
modelextract-lite2.9currentPlatform model council
policysegregation-of-dutiesv4currentInternal audit
promptorchestrator-briefp14currentChief of Staff office
prompttask-executionp21currentShared service engineering
toolsetread-only-lookupt12currentPlatform engineering
toolsetnotify-and-routet5currentPlatform engineering
toolsetdocument-fetcht9currentShared service engineering

Gates on this line

The control points this unit had to clear

Analyst review
Held for a named human when the unit exceeds the alert decision envelope, when confidence falls below the floor, or when a policy clause is engaged.
Approver: Director, Security Operations · not reached
Escalate incident
Held for a named human when the unit exceeds the alert decision envelope, when confidence falls below the floor, or when a policy clause is engaged.
Approver: Director, Security Operations · not reached

Records schedule and holds

How long this evidence must be kept, and whether it is frozen

TECH-3Y3 years
Technology change and access evidence
Security review and change audit requirement.
Deleted at three years from the change closing.

What this pack proves, and what it does not

Read this before you rely on it

It does prove
  • Every action carries a named actor, an actor kind, and a timestamp.
  • Every action names the authority grant that permitted it and the cap that grant carries.
  • Every action stamps the model, prompt, policy and tool versions in force at that moment.
  • Corrections are additive. A later record supersedes an earlier one and says why; the earlier record is never edited or deleted.
  • The chain is re-hashed live on this page, so a single altered field is detected immediately.
It does not prove
  • It is not tamper-proof against an attacker with write access to the store, who could rewrite the whole chain from genesis. Making that impossible requires publishing chain tips to a store this application cannot write to. That anchor is not built, and this page does not claim it.
  • The evidence in this demonstration is modeled from a simulated estate, not captured from production systems.
  • Identity here is the actor name recorded on the action. Cryptographic agent identity and signed attestation are a separate piece of work.