Deployment pattern
SOC/IR Evidence Package
A deployment pattern, not a shipped integration. After an incident involving an agent, the evidence bundle gives the investigator a signed, ordered record of the decisions the gateway recorded, checkable offline. It is not a complete account of the agent's actions or proof that a tool ran.
Security Operations
01
Target System
Security operations and incident response teams investigating an AI agent. A signed decision record can complement existing logs, signed-log systems and write-once retention. Compare the controls already in place before adding another evidence format.
02
What the gateway signs
- Each governed tool call
- PERMITTED or DENIED for every tools/call aga-proxy evaluates (except the calls known issue 7 on /security describes as refused without a receipt), with the tool name, an arguments hash, the reason and the SHA-256 of the policy's canonical JSON. aga-proxy's default profile, permissive, denies nothing on policy grounds; policy denial needs --profile standard or restrictive, or a --policy file in allowlist or denylist mode.
- The order
- Each receipt hash-links to the one before it, and a signed checkpoint binds the count, the head and the Merkle root.
- The export
- An evidence bundle the investigator verifies offline with aga-verify, against the gateway key pinned in advance.
03
What you build: not shipped
- Routing
- The agent's tool calls reach the gateway only if your deployment routes them there. Calls that go around it are not recorded.
- Custody
- Handing the bundle between investigators, and recording who held it, is your process. Nothing in the published packages signs custody transfers.
- Other evidence
- Logs, memory images and network captures stay in your existing tools. AGA does not collect or hash them.
04
What the record proves, and does not
- The integrity and order of every receipt present in the bundle, as the verifier parses it: a field name repeated in the file still verifies, because the verifiers read the last copy (known issue 5 on /security)
- Whether the record matches a separately obtained expected gateway key. Linking that key to an organization still needs a trusted mapping
- Not that the operator recorded every action, or that a permitted call ran
- Not the accuracy of timestamps: the gateway's clock is self-reported
Sample bundle
The same representative sample bundle offered site-wide: four Ed25519-signed receipts, Merkle proofs, a signed checkpoint, and an offline verifier. There is no incident-specific variant.