Agent Governance Evidence Pack

Keep a record of the work.
Make the checks easier to review.

When your agent uses Roam's run ledger and proof-bundle workflow, it can leave a reviewable record of changes, checks, and recorded decisions. The record helps you revisit the work; it does not prove that missing checks ran or certify compliance. Start with the agent checking guide.

Built on the free Apache 2.0 CLI · Local evidence storage and offline integrity checks · Tamper-evident ledger (HMAC-chained) · Optional attestations; signing and verification have their own key and network requirements

What's in the pack

Use the free CLI's run ledger and bundle workflow to collect these kinds of evidence. Start and bind the run, collect the checks you need, and inspect what is missing. The worked example shows the setup; installing Roam alone does not record every action.

1. Which agents changed what Inspect recorded run events, supplied agent details and repository identifiers with roam runs. HMAC chain verification checks record integrity, not the actor's identity or whether every command and file change was captured.
2. What context each agent read Collect pre-change checks such as roam preflight, roam impact and roam context. Inspect the recorded source locations and results; a saved tool call does not prove the agent read every returned file.
3. Risks accepted vs mitigated Keep findings beside the decisions and check results your workflow supplies. roam pr-bundle emit assembles the collected evidence; an absent decision or unexecuted test stays unverified.
4. Coordination and recorded approvals A lease records an agent's claim on named files or partitions and its expiry; a lease is not human approval. Preserve approval records separately with their source. Mode and policy controls have their own enforcement boundaries; leases alone do not block every edit or re-run.
5. Required and recorded checks Compare the required checks with the supplied execution records. Running a test does not automatically add it to a bundle, and a passing recorded test does not prove every risk was addressed. Inspect missing evidence and the verdict before deciding to ship.
+ Replay narrative roam replay <run_id> renders the recorded run events as a human-readable timeline — useful when a reviewer or auditor wants the story behind a specific PR without reading the raw JSON ledger.

All five evidence types ship as JSON (machine-readable), Markdown (human-readable), and an optional in-toto v1 attestation (signing and verification require a separately configured path).

The eight evidence questions

Use these eight questions to review an AI-assisted code change. Answer each from available evidence or mark it unverified. The sample report shows worked coverage with per-axis evidence rows, and evidence-checklist.md names the exact command for each axis.

Q1. Who acted? Per-run agent identity, model, MCP client id, and git author from roam runs show.
Q2. What authority existed? Mode, permits, leases, and policy decisions from roam mode, roam permit, roam lease.
Q3. What context was read? Pre-edit commands, symbols, and files from the bundle's context_read block.
Q4. What changed? Diff hash, commit SHA, and affected symbols from roam diff + roam pr-risk.
Q5. What could break? Blast radius and findings from roam preflight, roam impact, roam critique.
Q6. What policy applied? Rules config hash, constitution hash, and policy-decision events from roam runs show.
Q7. What verified it? Required vs run tests from the bundle's tests_required[] / tests_run[] reconciliation.
Q8. Who accepted risk? Authorizer and accepted-risk records from the bundle's approvals[] / accepted_risks[] arrays. Approvals recorded outside the substrate surface as redactions[].reason = "producer_not_available".

Sample report

Read the full Governance Pack sample report (schema governance-pack/1.0) for a complete deliverable example, with the eight-question coverage table, worked control-mapping, recommended next steps, and disclaimer block. Reproduce the same artifact extraction on your own repo with evidence-checklist.md; for the control map and wording-discipline rules, see control-mapping-README.md. The companion PR Replay sample covers merged-history detector replay (no run ledger required). For a redacted draft on your repository, email [email protected].

  1. 1 Generate locally. Run roam runs verify, roam pr-bundle emit --strict, and roam agent-score against an indexed repo, then feed the JSON envelopes through the render template. The substrate lives in src/roam/runs/, src/roam/pr_bundle/, and src/roam/evidence/.
  2. 2 Optional founder review. Ask about a by-request review of the run evidence you have retained. Agree scope, availability, price, data handling, and written terms before work starts. This is a custom report enquiry, not a separate subscription or a published 30/90-run package. For the existing merged-PR report offer, see PR Replay.
  3. 3 Hand to your auditor. The pack lands as Markdown + PDF + collected JSON. The reviewer can check the ledger's local-key HMAC integrity. Attestations and signatures are optional, separately configured outputs with their own verification requirements. The IP is yours; share it inside the audit scope without restriction.

Control mapping

Roam evidence to the controls auditors look for. The mapping documents what the pack supports; it does not claim formal conformity with any framework. Your auditor judges fit for your scope.

Roam evidence types mapped to SOC 2 CC8.1, ISO/IEC 42001, NIST AI RMF, and EU AI Act Article 12.
Roam evidence SOC 2 CC8.1 ISO/IEC 42001 NIST AI RMF EU AI Act Art. 12
Per-run ledger (HMAC-chained agent timeline) CC8.1 change tracking A.8.3 operational records Govern 1.4, Map 4.1 Automatic record-keeping
Recorded context and tool results CC8.1 change rationale A.6.2.2 design rationale Measure 2.8 traceability Traceability of decisions
Risk ledger (accepted vs mitigated) CC3.2 risk identification A.5.4 risk treatment Manage 1.3 risk response Risk-management evidence
Mode/policy records and separately supplied approvals CC6.3 access authorization A.6.1.2 authorization Govern 2.1 roles Human-oversight evidence
Required and recorded tests CC8.1 change verification A.8.4 verification Measure 2.5 validation Post-change verification
in-toto v1 attestation + cosign signature CC7.2 evidence integrity A.8.5 evidence integrity Measure 2.7 integrity Tamper-evident logs

Framework references: SOC 2 Trust Services Criteria (AICPA, 2017 with 2022 revisions); ISO/IEC 42001:2023 AI management system; NIST AI Risk Management Framework 1.0 (Jan 2023); EU Regulation 2024/1689 (AI Act), Article 12 "Record-keeping". Mapping is for evidence support; your conformity assessment is a separate engagement with qualified counsel and auditors. Repository check records are not a substitute for an AI system's operational logs.

Evidence support, not certification Roam Code provides evidence-export and control-mapping support for AI-agent change governance. This is evidence support, not formal certification. Roam does not perform compliance attestation; consult qualified counsel and auditors for formal certification against any framework.
Article 12 framing Article 12 addresses event logging by high-risk AI systems. Roam supplies development-check records, not the operational logs of a deployed AI system. Those records do not establish that Article 12 requirements are met. Consult qualified counsel to assess your system and the wider evidence it needs.
Scope The pack documents what an agent did against the local repository. It does not cover model-training evidence, dataset provenance, or production runtime behaviour. Those are outside Roam's measurement surface and require separate evidence.
Local analysis, explicit data paths Built in Athens. Ordinary analysis and evidence storage run locally, without automatic source-code upload. Connected agents and selected online features have separate data paths. Read the network boundary, the security policy, the trust & compliance posture page for current certification status, DPA, and roadmap posture, the security & procurement packet for the DPA, no-training commitment, and supply-chain posture, and architecture docs for what runs where. Tier pricing on /pricing.

Need help reviewing your retained run evidence? Email [email protected] with your repository, available records, and review questions. Custom work is quoted only after scope and availability are agreed. For current report prices and terms, see PR Replay.