Skip to content

Evidence

Evidence is an append-only, tenant-scoped account of the decisions and boundaries Axec actually enforced. An ActionRequest correlation joins policy evaluation, approval, execution or credential-release intent, upstream outcome, Data Protection, and terminal state into one ordered receipt.

Depending on the operation, evidence can include the final policy decision and reason, evaluator version, policy snapshot digest, approval outcome and expiry, dispatch marker, mediated upstream outcome, Data Protection categories and redaction counts, and the ActionRequest identifier.

Required evidence must be durable before Axec executes or releases a credential. If that boundary cannot be committed, Axec fails closed.

Evidence does not contain credentials, authorization headers, unrestricted MCP arguments, request bodies, raw upstream bodies, detected sensitive values, or detector samples. Retained results contain only bounded sanitized content.

For a credential release, evidence proves Axec released a credential under a governed decision. It does not claim that later direct use was observed, masked, or policy-enforced by Axec.

Use Evidence and auditing to investigate a receipt operationally.