Incident owners
You need a redacted chronology of supported evidence that can inform the next internal, legal, HR, or cybersecurity decision.
Review supported agent records to understand what happened in selected sessions: which commands ran, which files and tools were involved, where network activity pointed, what a person approved, and where the evidence stops.
Useful for Maine organizations investigating an unusual session, reviewing a sensitive workflow, preparing an internal incident record, or checking whether actual agent activity matched approved boundaries.
You need a redacted chronology of supported evidence that can inform the next internal, legal, HR, or cybersecurity decision.
You need to connect an agent identity or session to tools, files, commands, destinations, errors, and approvals.
You need to compare observed activity with policy, least-privilege expectations, and named human-control points.
Order supported prompts, tool calls, command activity, approvals, failures, and outcomes without reproducing unnecessary private content.
Identify supported evidence of files, tools, applications, commands, endpoints, and agent-to-agent delegation.
Mark visible human decisions, missing approvals, inherited user authority, and ambiguity about the acting identity.
Compare observed actions against the use case, assigned tools, permission boundary, and expected destinations.
Document deleted, unsupported, hosted, encrypted, expired, or otherwise unavailable evidence and its impact on confidence.
Translate evidence into concrete recommendations for access, approval, retention, logging, ownership, and escalation.
Define the relevant agent, time window, business concern, authorized reviewers, sensitive-data rules, and decisions the timeline must support.
Identify available supported records and document source, scope, access, retention, and gaps. Originals remain controlled by the client unless separately agreed.
Order relevant events and compare records across available agent, tool, approval, and system surfaces without treating a single signal as conclusive.
Remove unnecessary prompts, credentials, personal data, and client content; then present conclusions, confidence, limitations, and next actions.
Future recommendations favor unique owners, narrow credentials, visible approval events, durable but proportionate records, and a clear shutdown path. Least privilege limits the possible action set; human approval makes consequential exceptions explicit.
No. Coverage depends on supported agents, available local or platform records, retention, permissions, record integrity, and whether actions happened through observable tools. The audit documents gaps and confidence rather than filling them with assumptions.
No. The AI agent activity audit focuses narrowly on agent behavior, tools, files, commands, permissions, records, and selected sessions. The organization-wide AI audit covers broader policy, adoption, workforce, vendor, and governance questions.
No. Evidence and reports are handled within the agreed engagement scope. Public use, a case study, or disclosure requires separate written human approval and appropriate redaction.
Do not send private records through the public form. Describe the situation at a high level; secure evidence handling can be agreed after scope and confidentiality terms.