Get started

Public sector · evidence

Proving AI agent governance to oversight bodies.

An assurance case does not accept “the model decided.” It accepts a record that can be reconstructed, attributed to a decision, and checked independently after the fact.

The direct answer

Oversight bodies, internal audit functions and tribunals do not accept “the model decided” as a reason. Every AI agent action needs to be reconstructable after the fact, attributable to a specific decision and the human or system that authorised it, and provable to a party who was not there when it happened. That evidence has to survive an assurance case on its own terms, not on trust in the vendor who produced it. A self-hosted deployment is the structural way to keep both the system and the evidence trail inside your own accreditation boundary, where the risk owner who signs off the assurance case can actually inspect them.

In plain words

What it is, where it lives, when to reach for it

What is it
A guide to AI agent evidence in the public sector: oversight, accreditation boundaries and recorded human review.
Where do I use it
Inside your own accreditation boundary; the platform and its evidence trail both stay on your estate.
When would I use it
When a risk owner, auditor or tribunal will ask you to prove what an AI agent did and who approved it.
How do I use it
Read the direct answer above; verification runs offline from an evidence export, with no vendor account.

What reconstructable actually means

An audit trail an oversight body can check without trusting us.

“Reconstructable” is doing real work in that sentence. It means three specific things, not a general promise of good logging.

A signed, hash-chained row for every action
Each agent action, and each approval decision taken on it, is written as a structured event linked to the one before it. Altering or deleting a past entry breaks that chain in a way recomputation detects, so the record cannot be quietly edited after the fact.
An external witness
Signed tips of the chain are published outside the system that produced them. An oversight body can confirm the record has not been rewritten without being handed the underlying content, so witnessing does not require disclosure.
Verification that runs offline, against the file itself
An auditor with the evidence file, the public key and a verification tool can check integrity on a disconnected machine: no vendor account, no live system, no call to Quox. Internal audit or an oversight body checks the record itself, not a claim about it.

This is the evidence model in full: hash chain, signed tips, offline verification, walked end to end with a worked example. Read the deep dive for auditors.

Sovereignty

The evidence trail stays inside your accreditation boundary.

Quox is self-hosted first: it installs and runs on your own infrastructure, including sovereign and disconnected estates, rather than defaulting to a vendor's cloud.

That matters for citizen data, and it matters just as much for the audit trail itself, because governance records carry prompts, tool arguments, case references and the identity of the people who approved things. If a record is sensitive enough to need protecting, it is sensitive enough to stay inside the boundary the risk owner is actually accountable for.

Verification does not depend on connectivity either. The evidence file and the verification tool are enough on their own, which is what makes the model workable for air-gapped and disconnected environments: an auditor can check a record on an isolated machine with no route out, and get the same answer a connected system would give.

The full operational picture, including the honest cost of running it yourself and what disconnected operation actually requires, is in the self-hosted governance guide.

Human accountability

Meaningful human review, recorded as an event, not a policy statement.

Actions your policy marks as consequential are not left to run and get checked afterwards. An approval holds execution until a named human decides, the approval gate fails closed, and the approval itself lands in the trail alongside the action it covers.

The reviewer, the timing and the decision are part of the same hash-chained record as the action, so the evidence for meaningful human involvement is the same evidence that proves what the agent did, not a separate document assembled afterwards for the SIRO or the accountable risk owner to sign.

Stated plainly

What this page does and does not claim.

Quox holds no FedRAMP authorisation, and this page claims no certification or framework conformance.

The structural answer offered here is narrower and more honest than a certification claim: a self-hosted deployment keeps the system and its evidence trail inside your own accreditation boundary, where your own assurance process can inspect them directly, rather than asking an oversight body to take a vendor's word for it.

This page is not legal or accreditation advice; whether a given deployment satisfies a specific assurance case is a determination for your own risk owner and accreditor.

Start with the evidence, or the deployment model.

Read how the evidence chain works end to end, how self-hosted and disconnected deployment holds the boundary, or where the wider regulatory picture stands.