Governance

Designing Auditable AI Workflows

If you cannot explain why an agent made a decision six months ago, you cannot defend it. Auditability has to be designed in from the first sprint.

Written by
Owen Marsh
Published
Reading time
2 min
A calculator and pen resting on a sheet of figures

Sooner or later someone will ask why an agent did something. It might be a customer disputing a decision, an internal auditor, or a regulator. The question will arrive long after the run finished, and the people who built the system may have moved on.

Auditable workflows are the ones that can answer that question calmly.

Record decisions, not just outputs

Logging the final message is not enough. For each run, capture:

  • the input exactly as received,
  • the version of the prompt, tools and routing rules in use,
  • every model call with its response,
  • every tool call with its parameters and result,
  • the final action and whether a human approved it.

With this, any decision can be reconstructed step by step.

Version everything that shapes behaviour

An audit trail is only useful if you can tell which configuration produced a decision. Treat prompts, policies and tool definitions as versioned artefacts. Each run should record the exact versions it used, so “what changed?” has a precise answer.

Keep evidence close to the decision

When an agent relies on a document — a policy clause, a contract term, a help-centre article — store a reference to the specific version it read. Policies change; your record should show the one that applied at the time.

Separate who can change what

Good audit design mirrors good security design:

  1. Engineers can propose changes to prompts and tools.
  2. A named owner approves changes that affect decisions.
  3. Production configuration changes only through a reviewed deployment.

This makes the history trustworthy, not just complete.

Decide retention up front

Audit data contains customer information, so keep it for as long as you need to answer questions — and no longer. Agree the retention window with your legal and data protection colleagues before launch, and make sure deletion actually happens.

Make the trail readable

Raw logs satisfy a technical requirement, but people need a readable view. We build a simple replay screen: the input on the left, each step in order, the final action at the bottom. If a non-engineer can follow a run from start to finish, the workflow is genuinely auditable.

Auditability is not paperwork added at the end. It is the shape of the system from the first sprint.

  • Governance
  • Audit trails
  • Compliance
Keep reading

More from the run log on governance and the work around it.

Two pilot slots open this quarter

Stop evaluating AI. Start operating it.

Ninety minutes with your operations lead and one of our engineers. You leave with a scoped workflow, an honest feasibility call and a number.