M12 · Immutable trail · regulatory replay

Audit and evidence

Every routed intent, tool call, policy decision and override, in order, replayable.

$ python -m fde_toolkit audit

Workflow

the order an FDE actually runs it in

  1. 1Emit a structured event for every intent, tool call and decision.
  2. 2Append only — corrections are new events, never edits.
  3. 3Attribute each event to an agent or a named human actor.
  4. 4Chain hashes so ordering proves the guardrail ran before the action.
  5. 5Export JSONL to SIEM and GRC with retention and access control.

Function output

deterministic trace

{"ts":"2026-08-11T09:49:00+05:30","actor":"agent","event":"intent.route","route":"graph_agent","confidence":0.94}
{"ts":"...:01","actor":"agent","event":"tool.call","tool":"get_customer","risk":"low","approved":true}
{"ts":"...:02","actor":"policy_engine","event":"q_lock","decision":"REJECT_ISOLATE"}
{"ts":"...:03","actor":"human","event":"review.requested","queue":"AML_COMPLIANCE"}