Skip to main content
Deployment pattern

SOC/IR Evidence Package

A deployment pattern, not a shipped integration. After an incident involving an agent, the evidence bundle gives the investigator a signed, ordered record of the decisions the gateway recorded, checkable offline. It is not a complete account of the agent's actions or proof that a tool ran.

Security Operations
01

Target System

Security operations and incident response teams investigating an AI agent. A signed decision record can complement existing logs, signed-log systems and write-once retention. Compare the controls already in place before adding another evidence format.

02

What the gateway signs

Each governed tool call
PERMITTED or DENIED for every tools/call aga-proxy evaluates (except the calls known issue 7 on /security describes as refused without a receipt), with the tool name, an arguments hash, the reason and the SHA-256 of the policy's canonical JSON. aga-proxy's default profile, permissive, denies nothing on policy grounds; policy denial needs --profile standard or restrictive, or a --policy file in allowlist or denylist mode.
The order
Each receipt hash-links to the one before it, and a signed checkpoint binds the count, the head and the Merkle root.
The export
An evidence bundle the investigator verifies offline with aga-verify, against the gateway key pinned in advance.
03

What you build: not shipped

Routing
The agent's tool calls reach the gateway only if your deployment routes them there. Calls that go around it are not recorded.
Custody
Handing the bundle between investigators, and recording who held it, is your process. Nothing in the published packages signs custody transfers.
Other evidence
Logs, memory images and network captures stay in your existing tools. AGA does not collect or hash them.
04

What the record proves, and does not

  • The integrity and order of every receipt present in the bundle, as the verifier parses it: a field name repeated in the file still verifies, because the verifiers read the last copy (known issue 5 on /security)
  • Whether the record matches a separately obtained expected gateway key. Linking that key to an organization still needs a trusted mapping
  • Not that the operator recorded every action, or that a permitted call ran
  • Not the accuracy of timestamps: the gateway's clock is self-reported

Sample bundle

The same representative sample bundle offered site-wide: four Ed25519-signed receipts, Merkle proofs, a signed checkpoint, and an offline verifier. There is no incident-specific variant.