Back to workflows
Legal & complianceOrchestrate multiple stepsTeam

Audit evidence collection

Request, validate, and package control evidence while preserving provenance.

What this workflow does

Request, validate, and package control evidence while preserving provenance. It coordinates dependencies across connected systems, pauses at exception boundaries, and records the state of every approved sub-step.

What you gain

Source-linked audit evidence package

What the AI agent changes

How this worked before

A fixed workflow required every system and input to behave exactly as expected; one exception stopped the entire chain.

What the AI agent changes

The agent chooses the next tool from the current state, recovers from common exceptions, and asks for a decision at the right boundary.

Agent trigger

An audit request list or recurring control window opens.

Inputs

  • Process context: PBC request, control owner, evidence rules, and system records
  • Approved policies, ownership, and exception rules

Agent flow

  1. 1

    Build the dependency graph and verify every connector permission.

  2. 2

    Coordinate read-only sub-steps and surface blocked dependencies.

  3. 3

    Prepare evidence completeness and exception status with state, exceptions, and rollback points.

  4. 4

    Execute approved sub-steps idempotently and verify the final state.

Human decisions

After step 3

The accountable process owner approves evidence completeness and exception status.

Outcome

  • Source-linked audit evidence package
  • Evidence, exceptions, and audit trail

Guardrails

  • Pause when a dependency or approval is missing.
  • Record before-and-after state for every system write.

Risks and mitigations

A partial multi-system execution can leave records in conflicting states.

Use idempotency keys, checkpoints, and explicit compensation for every write step.

Sources and evidence