Evidence
Evidence is an append-only, tenant-scoped account of the decisions and boundaries Axec actually enforced. An ActionRequest correlation joins policy evaluation, approval, execution or credential-release intent, upstream outcome, Data Protection, and terminal state into one ordered receipt.
What Axec records
Section titled “What Axec records”Depending on the operation, evidence can include the final policy decision and reason, evaluator version, policy snapshot digest, approval outcome and expiry, dispatch marker, mediated upstream outcome, Data Protection categories and redaction counts, and the ActionRequest identifier.
Required evidence must be durable before Axec executes or releases a credential. If that boundary cannot be committed, Axec fails closed.
What Axec deliberately excludes
Section titled “What Axec deliberately excludes”Evidence does not contain credentials, authorization headers, unrestricted MCP arguments, request bodies, raw upstream bodies, detected sensitive values, or detector samples. Retained results contain only bounded sanitized content.
For a credential release, evidence proves Axec released a credential under a governed decision. It does not claim that later direct use was observed, masked, or policy-enforced by Axec.
Use Evidence and auditing to investigate a receipt operationally.