You need a history of access decisions: who granted each access, who approved it, and when it changed. A screenshot of today’s settings proves today’s state and nothing else. That history is what a sealed audit chain records, where every entry is linked to the previous one: rewriting a past entry breaks the seal of every entry after it, and shows at verification.
The day the question lands
The auditor’s email fits in one sentence: “please send us the list of processing activities where an AI accesses customer data, with the corresponding permissions and their history”. The request sounds reasonable, and it is. The answer is where the trouble starts.
The team spends two meetings on it. People go from tool to tool, open the settings pages and take screenshots. What the file contains at the end is a stack of screenshots that prove the state of things today and nothing more. Nobody can say what the AI was allowed to read six months ago, who granted the current accesses, or who signed them off. Yet that is precisely what the auditor is asking for.
What an auditor actually accepts as evidence
An auditor is not in the business of believing you. Their job is to verify. A written declaration commits them to nothing, and a screenshot only proves the instant it was taken. What they accept as evidence is a record that carries three things: the author of the decision, the person who approved it, and the date. They also need assurance that the record was not rewritten after the fact, at the exact moment the question became uncomfortable.
That is what a sealed audit chain does. Every access decision is written as an entry, and every entry is linked to the one before it. Altering a past entry breaks the seal on everything that follows, and verification detects it. Nobody is asked to believe the history any more; it gets verified. This difference between a setting you take on trust and a decision you can prove is the heart of context governance.
Where those records come from
An audit chain is only worth something if it records real decisions. In Kastel, the company’s memory is governed: every person has a read scope attached to their responsibility, and an AI working for someone reads only what that person is allowed to read. We walk through this mechanism in who can see what when an AI plugs in.
Every change to that scope goes through human approval before it takes effect, and it is that decision, with its author, its approver and its date, that gets written to the chain. On the day the email arrives, the answer already exists: it was recorded at the moment each access was granted, changed or withdrawn. There is nothing to reconstruct, and nothing to reconstruct from memory.
The file at the scale of an organisation
A local audit chain answers for one deployment. An organisation running several deployments, or a regulated account, has to answer more broadly, and its file holds three additional pieces. The consolidated audit gathers the chains of several deployments into a single view, which is the one an auditor asks for when they audit the organisation rather than a server. Signed attestations let you hand over an extract whose origin can be checked. External anchoring regularly places the chain’s fingerprint outside your walls, which lets a third party verify the history without having to believe you, or us.
That file belongs to the Enterprise plan. Governance itself, with responsibility-based scopes, human approval and the sealed local audit, is part of the free core and is not for sale.
Check it before you talk to us
Everything in this article can be tested without asking our permission. The Kastel core installs for free on your own infrastructure, through the command line and MCP. Plug in your own AI keys, grant an access, change it, withdraw it, then ask for the history: all three decisions are there, each with its author, its approver and its date. Then export your entire context and see for yourself that it leaves with you if you go.
The underlying question, where your company’s memory should live, gets settled in the same place: with you.