Workstation baseline
Which devices met the baseline?
Ownership, dates and eight baseline checks. Failed and unobserved checks stay visible; this is not the full SOC 2 control set.
Show which policy governed an agent action and what Node decided. Export records from Cloud for security reviews and compliance workflows.
A signature and a complete action history answer different questions. We ran the Node verifier against an intact bundle, an altered record and a bundle with a missing batch.
Two signed batches contain four receipts. The verifier accepts the signatures and the action lifecycle is complete.
Executed September 9, 2026 using commercial Oktsec Node and synthetic test data. These are recorded results, not a live browser scan. Verification covers included batches; it does not prove that every batch was exported. Test method and provenance.
AI agent audit evidence connects a recorded action to its available identity context, policy decision and result. Oktsec adds signed action records and exportable system and policy observations to support security and compliance reviews.
Which devices met the baseline?
Ownership, dates and eight baseline checks. Failed and unobserved checks stay visible; this is not the full SOC 2 control set.
What policy was deployed?
Policy coverage, reported state, exceptions and change history, with references to relevant SOC 2 and ISO 27001 controls.
What changed during the review?
Recorded agent activity and administrative changes. Preserve the selected period, systems and export limits.
Can I verify the action record?
Node-signed receipts and lifecycle chains. Use the commercial Node verifier with an independently trusted node fingerprint.
Start with the auditor’s question and the systems and dates in scope. Export the relevant records, verify signed evidence where available, and attach the files to the auditor’s workspace. Native Vanta and Drata connectors are not currently available.
Missing evidence stays missing. An unobserved check is not a pass. Actions that bypass the configured integration are outside its record.
Your auditor assesses sufficiency. Control mappings organize evidence; they do not establish certification or a successful audit.
An AI agent audit trail records actions and their context, such as the caller, time, requested operation and outcome. Oktsec Node records covered actions at the configured integration; Cloud organizes the evidence for review and export.
An activity log helps reconstruct recorded events. A signed action-evidence bundle additionally lets a reviewer check receipt hashes, signatures and lifecycle chains against an independently trusted node identity. These checks verify the included evidence; they do not prove that all activity was captured or exported.
Oktsec provides supporting workstation observations, policy review reports, activity exports and signed action evidence. The organization and auditor determine the applicable controls, evidence sufficiency and audit outcome. Oktsec does not automatically make an organization SOC 2 compliant.
The current workflow is export-and-upload: select the relevant records in Oktsec and attach them in your compliance platform or auditor workspace. Confirm accepted formats and requirements with your reviewer. A native Oktsec connector is not currently provided.
Yes. The verifier supplied with the commercial Oktsec Node deployment can check an exported action-evidence bundle without a network connection or database. Supply the enrolled node fingerprint from an independent trusted source, then review the reported integrity, lifecycle completeness and coverage.
No. The verifier checks the batches included in the bundle. It cannot prove that no batch was left out. Review export limits, period and integration coverage along with the verification result.
Tell us which workflow, review period and control you need to support. We will identify the records to evaluate with your team.