DocsSign inInstall Kastel
All articles
Proof and audit

How do you prove to an auditor what an AI was allowed to read?

A screenshot of your settings proves the state of things today. An auditor asks for the history of access decisions, and there is a way to already have it when they do.

By Alexis PratJuly 31, 20264 min read
The short answer

You need a history of access decisions: who granted each access, who approved it, and when it changed. A screenshot of today’s settings proves today’s state and nothing else. That history is what a sealed audit chain records, where every entry is linked to the previous one: rewriting a past entry breaks the seal of every entry after it, and shows at verification.

The day the question lands

The auditor’s email fits in one sentence: “please send us the list of processing activities where an AI accesses customer data, with the corresponding permissions and their history”. The request sounds reasonable, and it is. The answer is where the trouble starts.

The team spends two meetings on it. People go from tool to tool, open the settings pages and take screenshots. What the file contains at the end is a stack of screenshots that prove the state of things today and nothing more. Nobody can say what the AI was allowed to read six months ago, who granted the current accesses, or who signed them off. Yet that is precisely what the auditor is asking for.

What an auditor actually accepts as evidence

An auditor is not in the business of believing you. Their job is to verify. A written declaration commits them to nothing, and a screenshot only proves the instant it was taken. What they accept as evidence is a record that carries three things: the author of the decision, the person who approved it, and the date. They also need assurance that the record was not rewritten after the fact, at the exact moment the question became uncomfortable.

That is what a sealed audit chain does. Every access decision is written as an entry, and every entry is linked to the one before it. Altering a past entry breaks the seal on everything that follows, and verification detects it. Nobody is asked to believe the history any more; it gets verified. This difference between a setting you take on trust and a decision you can prove is the heart of context governance.

Access granted - author, approver, dateScope changed - approved, datedAccess withdrawn - tracedSealed: rewriting the past breaks the seal
Every access decision is written as an entry linked to the previous one; tampering with the history breaks the seal.

Where those records come from

An audit chain is only worth something if it records real decisions. In Kastel, the company’s memory is governed: every person has a read scope attached to their responsibility, and an AI working for someone reads only what that person is allowed to read. We walk through this mechanism in who can see what when an AI plugs in.

Every change to that scope goes through human approval before it takes effect, and it is that decision, with its author, its approver and its date, that gets written to the chain. On the day the email arrives, the answer already exists: it was recorded at the moment each access was granted, changed or withdrawn. There is nothing to reconstruct, and nothing to reconstruct from memory.

The file at the scale of an organisation

A local audit chain answers for one deployment. An organisation running several deployments, or a regulated account, has to answer more broadly, and its file holds three additional pieces. The consolidated audit gathers the chains of several deployments into a single view, which is the one an auditor asks for when they audit the organisation rather than a server. Signed attestations let you hand over an extract whose origin can be checked. External anchoring regularly places the chain’s fingerprint outside your walls, which lets a third party verify the history without having to believe you, or us.

That file belongs to the Enterprise plan. Governance itself, with responsibility-based scopes, human approval and the sealed local audit, is part of the free core and is not for sale.

Check it before you talk to us

Everything in this article can be tested without asking our permission. The Kastel core installs for free on your own infrastructure, through the command line and MCP. Plug in your own AI keys, grant an access, change it, withdraw it, then ask for the history: all three decisions are there, each with its author, its approver and its date. Then export your entire context and see for yourself that it leaves with you if you go.

The underlying question, where your company’s memory should live, gets settled in the same place: with you.

An audit is prepared before the email arrives

If your organisation must be able to hand over an audit file on its use of AI, the Enterprise plan builds that file continuously, decision by decision.

See the Enterprise plan