Agent Governance Evidence Pack
Keep a record of the work.
Make the checks easier to review.
When your agent uses Roam's run ledger and proof-bundle workflow, it can leave a reviewable record of changes, checks, and recorded decisions. The record helps you revisit the work; it does not prove that missing checks ran or certify compliance. Start with the agent checking guide.
Built on the free Apache 2.0 CLI · Local evidence storage and offline integrity checks · Tamper-evident ledger (HMAC-chained) · Optional attestations; signing and verification have their own key and network requirements
What's in the pack
Use the free CLI's run ledger and bundle workflow to collect these kinds of evidence. Start and bind the run, collect the checks you need, and inspect what is missing. The worked example shows the setup; installing Roam alone does not record every action.
1. Which agents changed what
Inspect recorded run events, supplied agent details and repository
identifiers with roam runs. HMAC chain verification
checks record integrity, not the actor's identity or whether every
command and file change was captured.
2. What context each agent read
Collect pre-change checks such as roam preflight,
roam impact and roam context. Inspect
the recorded source locations and results; a saved tool call does
not prove the agent read every returned file.
3. Risks accepted vs mitigated
Keep findings beside the decisions and check results your workflow
supplies. roam pr-bundle emit assembles the collected
evidence; an absent decision or unexecuted test stays unverified.
4. Coordination and recorded approvals
A lease records an agent's claim on named files or partitions and
its expiry; a lease is not human approval. Preserve approval
records separately with their source. Mode and policy controls
have their own enforcement boundaries; leases alone do not block
every edit or re-run.
5. Required and recorded checks
Compare the required checks with the supplied execution records.
Running a test does not automatically add it to a bundle, and a
passing recorded test does not prove every risk was addressed.
Inspect missing evidence and the verdict before deciding to ship.
+ Replay narrative
roam replay <run_id> renders the recorded
run events as a human-readable timeline — useful when a
reviewer or auditor wants the story behind a specific PR
without reading the raw JSON ledger.
All five evidence types ship as JSON (machine-readable), Markdown (human-readable), and an optional in-toto v1 attestation (signing and verification require a separately configured path).
The eight evidence questions
Use these eight questions to review an AI-assisted code change. Answer each from available evidence or mark it unverified. The sample report shows worked coverage with per-axis evidence rows, and evidence-checklist.md names the exact command for each axis.
Q1. Who acted?
Per-run agent identity, model, MCP client id, and git author from roam runs show.
Q2. What authority existed?
Mode, permits, leases, and policy decisions from roam mode, roam permit, roam lease.
Q3. What context was read?
Pre-edit commands, symbols, and files from the bundle's context_read block.
Q4. What changed?
Diff hash, commit SHA, and affected symbols from roam diff + roam pr-risk.
Q5. What could break?
Blast radius and findings from roam preflight, roam impact, roam critique.
Q6. What policy applied?
Rules config hash, constitution hash, and policy-decision events from roam runs show.
Q7. What verified it?
Required vs run tests from the bundle's tests_required[] / tests_run[] reconciliation.
Q8. Who accepted risk?
Authorizer and accepted-risk records from the bundle's approvals[] / accepted_risks[] arrays. Approvals recorded outside the substrate surface as redactions[].reason = "producer_not_available".
Sample report
Read the full
Governance Pack sample report
(schema governance-pack/1.0) for a complete deliverable
example, with the eight-question coverage table, worked
control-mapping, recommended next steps, and disclaimer block.
Reproduce the same artifact extraction on your own repo with
evidence-checklist.md;
for the control map and wording-discipline rules, see
control-mapping-README.md.
The companion
PR Replay sample
covers merged-history detector replay (no run ledger required).
For a redacted draft on your repository, email
[email protected].
-
1
Generate locally.
Run
roam runs verify,roam pr-bundle emit --strict, androam agent-scoreagainst an indexed repo, then feed the JSON envelopes through the render template. The substrate lives insrc/roam/runs/,src/roam/pr_bundle/, andsrc/roam/evidence/. - 2 Optional founder review. Ask about a by-request review of the run evidence you have retained. Agree scope, availability, price, data handling, and written terms before work starts. This is a custom report enquiry, not a separate subscription or a published 30/90-run package. For the existing merged-PR report offer, see PR Replay.
- 3 Hand to your auditor. The pack lands as Markdown + PDF + collected JSON. The reviewer can check the ledger's local-key HMAC integrity. Attestations and signatures are optional, separately configured outputs with their own verification requirements. The IP is yours; share it inside the audit scope without restriction.
Control mapping
Roam evidence to the controls auditors look for. The mapping documents what the pack supports; it does not claim formal conformity with any framework. Your auditor judges fit for your scope.
| Roam evidence | SOC 2 CC8.1 | ISO/IEC 42001 | NIST AI RMF | EU AI Act Art. 12 |
|---|---|---|---|---|
| Per-run ledger (HMAC-chained agent timeline) | CC8.1 change tracking | A.8.3 operational records | Govern 1.4, Map 4.1 | Automatic record-keeping |
| Recorded context and tool results | CC8.1 change rationale | A.6.2.2 design rationale | Measure 2.8 traceability | Traceability of decisions |
| Risk ledger (accepted vs mitigated) | CC3.2 risk identification | A.5.4 risk treatment | Manage 1.3 risk response | Risk-management evidence |
| Mode/policy records and separately supplied approvals | CC6.3 access authorization | A.6.1.2 authorization | Govern 2.1 roles | Human-oversight evidence |
| Required and recorded tests | CC8.1 change verification | A.8.4 verification | Measure 2.5 validation | Post-change verification |
| in-toto v1 attestation + cosign signature | CC7.2 evidence integrity | A.8.5 evidence integrity | Measure 2.7 integrity | Tamper-evident logs |
Framework references: SOC 2 Trust Services Criteria (AICPA, 2017 with 2022 revisions); ISO/IEC 42001:2023 AI management system; NIST AI Risk Management Framework 1.0 (Jan 2023); EU Regulation 2024/1689 (AI Act), Article 12 "Record-keeping". Mapping is for evidence support; your conformity assessment is a separate engagement with qualified counsel and auditors. Repository check records are not a substitute for an AI system's operational logs.
Need help reviewing your retained run evidence? Email [email protected] with your repository, available records, and review questions. Custom work is quoted only after scope and availability are agreed. For current report prices and terms, see PR Replay.