# Prove what every model did

> Answer an auditor's "what did the AI actually do" with proof, not a log line they have to trust.

When an auditor, an investigator, or a customer asks what an AI system actually did, plain logs are a weak answer. They can be edited or deleted, and a single line gives nobody a way to independently verify what a model was asked or what it returned. As AI reaches regulated workflows, that gap turns into a liability.

## What you can do

- Record every interaction on a surface, whether it succeeded, was blocked, or failed, so that you hold a complete transcript of what entered, how it was processed, and what left.

- Capture per-call cost, latency, tokens, and each guardrail verdict so that you can show who called what, and why it passed or was blocked.

- Sign every record as a Verifiable Credential and chain it by content hash so that deletion or tampering is detectable, not just individual forged records.

- Export the signed trail to your SIEM or observability stack so that security and finance work from one source of truth.

## How it works

Governance recording is enabled per surface, off by default. Once on, every interaction is written into a Governance Record: an ordered list of the processing stages that ran, each with its verdict, plus the prompt, the completion, and the metrics for the call. Each record is wrapped in a W3C Verifiable Credential and signed with the appliance’s own key, tied to its Decentralised Identifier, and every record embeds the content hash of the previous record on the same surface, forming a per-surface hash chain. Records are encrypted at rest with AES-256-GCM, the caller identity is stored as a salted hash rather than a raw identifier, and each signed record can also be exported to OpenTelemetry or an integration such as a webhook, a SIEM, or a streaming bus.

A surface’s chain can be verified on demand: verification recomputes every record’s content hash and walks the links, returning a pass or fail with the number of records checked, so a deleted or reordered record is detectable rather than silent. With body capture turned off, the appliance keeps cryptographic digests only, still proving what content flowed without storing the raw text.

## Related

- [Governance records](/products/affinidi-trust-fabric/agent-stream/concepts/governance-records.md): The record contents, per-record signature, and hash-chain verification in full.

- [Observability](/products/affinidi-trust-fabric/agent-stream/concepts/observability.md): The operational telemetry and rejection taxonomy that sit alongside the signed trail.

- [Telemetry and exports](/products/affinidi-trust-fabric/agent-stream/reference/observability/telemetry-and-exports.md): How to route traces, metrics, and records to your own stack.

- [Security and access control](/products/affinidi-trust-fabric/agent-stream/concepts/security-and-access-control.md): The encryption and identity-hashing model that protects record contents.
