Developer builds policy-as-code audit tool to verify if AI agent runs were permitted
A developer has added a policy-as-code audit feature to the open-source project agent-lab-trust, designed to check whether AI agent runs complied with declared rules — not just whether they succeeded. The tool evaluates cost caps, call limits, required output artifacts, and forbidden markers, then generates a canonical audit hash for each run. Testing across 13 archived synthetic GenMentor runs showed that a mismatched default contract failed all 13, while the correctly declared GenMentor contract passed all 13 — with the underlying data unchanged. The project distinguishes between operational dashboards that show what happened and governance tooling that shows what was permitted under a specific policy. The tool is reproducible via Docker and is the third installment in a series on making AI agent behavior verifiable and auditable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in