M12 · Immutable trail · regulatory replay
Audit and evidence
Every routed intent, tool call, policy decision and override, in order, replayable.
$ python -m fde_toolkit audit
Workflow
the order an FDE actually runs it in
- 1Emit a structured event for every intent, tool call and decision.
- 2Append only — corrections are new events, never edits.
- 3Attribute each event to an agent or a named human actor.
- 4Chain hashes so ordering proves the guardrail ran before the action.
- 5Export JSONL to SIEM and GRC with retention and access control.
Function output
deterministic trace
{"ts":"2026-08-11T09:49:00+05:30","actor":"agent","event":"intent.route","route":"graph_agent","confidence":0.94}
{"ts":"...:01","actor":"agent","event":"tool.call","tool":"get_customer","risk":"low","approved":true}
{"ts":"...:02","actor":"policy_engine","event":"q_lock","decision":"REJECT_ISOLATE"}
{"ts":"...:03","actor":"human","event":"review.requested","queue":"AML_COMPLIANCE"}