Workflow module
Monitoring, incidents, and reassessment
Keep the record alive after go-live — and reassess before it silently goes stale.
Keep the record alive after go-live — and reassess before it silently goes stale.
Why it matters
A record captured once is only true for a moment. Agents drift, data changes, models get deprecated, and frameworks move. If the record freezes at approval it quietly stops being true the day after it prints.
What good looks like
Monitoring records what is watched, on what cadence, and by whom, using the same control-status states — usage counts as monitored only when monitoring is Implemented with a real cadence. Incidents are logged with a lifecycle (Open, Investigating, Mitigated, Resolved, Closed) and a severity, so Open and Investigating stay visible as live gaps. When a tracked source, framework, or model genuinely changes, the affected agents are marked 'reassessment recommended' — nothing is rewritten automatically, and previously frozen packs stand exactly as they were.
What can go wrong
The record freezes at approval and goes out of date. 'We monitor it' has no cadence and no owner. Incidents live in a chat thread and are marked done without a real resolution state. A model reaches end-of-life or a guideline moves, and old records are quietly wrong with nothing flagging it.
What AgentProof checks
AgentProof reuses the control-status machine for monitoring (a cadence is required before usage counts as monitored) and runs a five-state incident machine that keeps Open and Investigating visible. The Radar tracks governance, regulatory, model, and failure-mode sources and recommends reassessment for the specific affected agents — it proposes, never applies, and never rewrites scores or frozen packs. The decision to revisit stays with your team.
Key terms
The exact vocabulary this part of the record uses — grounded in the shipped product model.
- Monitoring status
- Reuses control_status plus a cadence requirement before usage counts as monitored.
- Incident states
- open, investigating, mitigated, resolved, closed — open and investigating stay visible.
- Severity
- low, medium, high, critical.
- Reassessment recommended
- A Radar flag on the specific affected agents when a tracked source changes; it proposes, never applies.
- Frozen-pack immutability
- A reassessment mints a new pack version; the prior frozen pack is left byte-untouched.
- Materiality
- non_material through critical_material, with affected-eval defaulting to unknown_requires_review.
Keep reading
Build this record for your own agents
AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.
Ready to build a compliance-readiness record for your own agent?
Request a compliance readiness pilot to apply this guidance to a real agent.
AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.