Audit AI Agent Actions
When an AI agent reaches a sensitive resource, security teams need to know who, what, and when. Cup’n’String is designed to attribute agent activity and record policy decisions into audit evidence.
Why this matters
AI agents act on behalf of developers across many tools and providers. Without attribution and audit, it is hard to answer basic questions during a review or incident.
Which agent accessed a local database or API?
Which provider did an agent send data to?
Which MCP tools were invoked, and with what scope?
Was a sensitive credential path touched?
What policy decision applied, and when?
The Cup’n’String approach
Cup’n’String produces audit evidence from governed activity, attributing requests and recording policy outcomes.
Attributes outbound activity to a tool, agent, or identity
Records tool calls, provider requests, and MCP activity where routed through supported paths
Logs policy decisions, including allows, warns, and blocks
Supports tamper-evident audit records with HMAC-based integrity checks
Inspect decision records, verify evidence, and export signed packs with explicit completeness status
Keeps evidence under your control in self-hosted deployments
How it works
- Step 1Governed AI agent activity
- Step 2Attribution & policy evaluation
- Step 3Audit event recording
- Step 4Admin visibility & review
- Step 5Export for compliance
Checklist
- Can you attribute agent activity to an identity?
- Can you see which providers received data?
- Can you record MCP tool usage?
- Can you log policy decisions?
- Can you produce tamper-evident records?
- Can you keep evidence in your own environment?
Frequently asked questions
Can Cup’n’String help with audits?
Yes. It can provide visibility into governed AI agent activity, provider access, MCP tool usage, local service exposure, and policy decisions, helping security and platform teams understand how AI development tools are being used.
Is the audit trail tamper-evident?
Audit records support HMAC-based integrity checks. Signed evidence packs support verification and report completeness separately: a valid signature does not mean the evidence is complete. Coverage depends on activity routed through supported governance paths.
Does it collect source code?
No. The focus is local policy enforcement, traffic attribution, tool governance, and secret shielding rather than collecting source code.
Where is audit data stored?
In self-hosted deployments, audit data, keys, and telemetry stay inside your private cloud or on-premises network.
Make AI agent activity reviewable
Attribute activity, record policy decisions, and keep audit evidence under your control.