Workflow module
The evidence register
One evidence store per agent, where received is never quietly counted as accepted and a stale document never hides in green.
One evidence store per agent, where received is never quietly counted as accepted.
Why it matters
A compliance-readiness record is only as good as what backs it. The evidence register turns 'we handled that' into something a stakeholder can actually open — every material claim linked to an evidence item with an honest state, so the difference between a document arriving and a document being reviewed and accepted is never lost.
What good looks like
Every material claim links to an evidence item carrying an honest lifecycle state — Missing, Requested, Received, Accepted, Stale, or Rejected. Received is visibly not Accepted. An item past its review or expiry date reads as Stale regardless of the stored state. One store links out to the agent, environment, intake question, control, obligation, profile, test, vendor, approval, and monitoring records, so evidence is never orphaned in a folder somewhere.
What can go wrong
Evidence lives in scattered folders and inboxes. 'Received' is treated as 'done'. Documents silently expire. A control is marked implemented with nothing actually proving it, and no one notices until a stakeholder asks to see the proof.
What AgentProof checks
AgentProof holds the six-state evidence machine as a product invariant, flags an item stale by its review or expiry date, and exposes whether a control has accepted, non-stale evidence — so an implemented control with none surfaces as Needs evidence. It measures how much of the record is backed by accepted evidence versus merely asserted. That is coverage, never a compliance score.
Key terms
The exact vocabulary this part of the record uses — grounded in the shipped product model.
- Evidence types
- policy, log, screenshot, vendor_doc, contract, DPIA, risk_assessment, test_result, human_oversight_doc, incident_record, model_card, data_sheet, other.
- Link targets
- agent, environment, question, control, obligation, profile, test, vendor, approval, monitoring.
- Status
- missing, requested, received, accepted, stale, rejected — received is never quietly accepted.
- Confidence
- high, medium, low, unknown — an honest confidence read on the evidence item.
- Stale rule
- An item past its review or expiry date reads as Stale regardless of the stored state.
Keep reading
Build this record for your own agents
AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.
Ready to build a compliance-readiness record for your own agent?
Request a compliance readiness pilot to apply this guidance to a real agent.
AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.