DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

Audit Lineage & Draft Evidence | Forseti AI

Overview Image

Why Audit Lineage & Draft Evidence Matters

When a regulatory inspector asks "what did the AI say about this?", the customer needs a defensible answer. A summary screenshot is not enough. A chat transcript is not enough. The inspector wants the lineage: which record the assistant was looking at, which regulatory packs it had access to, which tool calls it made, which citations came back, which artifacts it produced, who approved them, and when.

Forseti's audit lineage view assembles all of that automatically. Every chat, every tool call, every workflow run, every draft, every approval transition flows through the same immutable audit trail as the rest of the platform. The chain-of-custody anchor that protects ordinary platform events protects every Forseti event too. The tamper-evident proof tap is emitted nightly; auditors can verify the chain end to end.

The draft-evidence layer is the other half of the picture. AI-generated evidence is created as draft-only. The approval transition (moving evidence from draft_ai_generated to approved) is enforced as a human action; the AI cannot transition its own evidence. The transition is recorded in the audit trail with the approving operator and the time of approval.

The point is not that Forseti is always right. The point is that every claim is cited, every artifact is reviewable, every interaction is in the chain of custody, and the customer can hand over a defensible answer.

Audit Lineage & Draft Evidence Features

Reading Audit Lineage

Walk the chain from a regulatory citation back to the source record

Open a lineage view from any AI-touched record. The view shows every chat that referenced the record, every tool call that ran against it, every citation that came back, every task generated, every draft produced, every approval transition. Filter by source (chat / workflow / MCP / scheduled), by persona, by time window.

  • Per-record lineage with filter chips
  • Walks from citation back to source record
Reading Audit Lineage

Tracing AI-Touched Evidence

Follow an evidence artifact back through its full AI provenance

For any AI-generated evidence (a draft regulator letter, a draft DPIA narrative, a draft remediation plan) open the trace view. The view shows the workflow run that produced the draft, the chat that initiated it (if any), the tool calls behind the citations, the operator who approved or rejected, and the linked downstream records.

  • Per-evidence provenance graph
  • Linked downstream record references
Tracing AI-Touched Evidence

Approving Draft Evidence

Human-only approval transition for AI-generated evidence

AI-generated evidence is created as draft_ai_generated. The transition to approved is enforced as a human action, the AI cannot transition its own evidence under any code path. The approval queue shows draft evidence per record with the underlying citations and the suggested approval action. The operator approves or rejects per item; both transitions are recorded.

  • Approval queue per record
  • Per-item approve or reject
Approving Draft Evidence

IAT Integration

Forseti events flow through the platform's Immutable Audit Trail

Every Forseti event (chats, tool calls, workflow runs, evidence drafts, redline reviews, memory curation, MCP calls, write approvals) is integrated into the platform's Immutable Audit Trail. The same chain-of-custody anchor that protects every other audit event in ComplianceOne protects every Forseti event. The tamper-evident proof tap is emitted nightly; auditors can verify the chain end to end.

  • All Forseti events in the IAT chain
  • Nightly tamper-evident proof tap
IAT Integration

WHAT FORSETI WILL NOT DO

The constraints are the product.

The features ride on top.

The constraints are the product.
Built for Trust.

Built for Trust.

Every guardrail is intentional.

Nothing is left to chance.

Designed for Audit.

Designed for Audit.

Every decision is traceable.

Every action leaves a trail.

Auto-Approve Evidence

Auto-Approve Evidence

No AI can approve its own evidence. Approval is always a human action, including MCP-initiated runs.

Alter Audit Trails

Alter Audit Trails

No audit-trail entry can be changed. Approvals, rejections, declines, expirations, and pending writes remain preserved.

Leak Lineage Data

Leak Lineage Data

No cross-organisation lineage exposure. Lineage views remain scoped to the customer organisation only.

Hide Audit Events

Hide Audit Events

No selective omission. Rejected suggestions, declined approvals, and expired pending writes always remain visible.

Background Image

See Audit Lineage & Draft Evidence in Action

Ready to see how a draft regulator letter traces back through its citations, tool calls, and approval transitions? Request a personalised demo.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

Next Steps

Icon Image

Start a Compliance Pilot

Pilot Forseti against your own privacy and compliance records. Walk the audit lineage for the AI-generated drafts and see the chain-of-custody hold up against your audit standard.

Icon Image

Discuss Your Compliance Needs

Talk to our team about how the lineage view fits into your existing audit process and inspection-readiness posture.

Frequently Asked Questions About Forseti Audit Lineage & Draft Evidence

No. AI-generated evidence is created as draft_ai_generated. The transition to approved is enforced as a human action under every code path; direct chat, workflow run, scheduled run, MCP-initiated run. There is no AI tool, no MCP tool, no scheduled job that can transition evidence to approved.

Yes. The lineage view is comprehensive; it includes accepted edits, rejected suggestions, approved drafts, declined drafts, expired pending writes, and any other meaningful state transition. The view does not filter "uncomfortable" events; the chain-of-custody is the chain-of-custody.

Every legal claim Forseti makes carries an inline citation naming the framework and the specific requirement. The lineage view links each citation to the tool call that produced it (the regulatory-search invocation) and from there to the regulatory pack source. Auditors can verify that the cited text was retrieved from the installed pack, not synthesised from training data.

Yes. The platform's Immutable Audit Trail emits a tamper-evident hash chain nightly. Auditors can verify the chain end to end. The same anchor protects every Forseti event — chats, tool calls, workflow runs, drafts, approvals, MCP calls.

Records do not delete; they soft-delete with a retention window. Lineage attached to a soft-deleted record remains visible in the audit trail; the lineage is not removed when the record is soft-deleted. After the retention window, hard deletion proceeds through the platform's standard deletion workflow with full audit-trail logging.