GOVERNANCE AND AUDIT
What the firm did with the AI, on whose authority, and whether the checks passed.
One chronological audit and compliance register. Not five tables and a spreadsheet someone maintains by hand.
| Date | Event | Matter | Actor | Result |
|---|---|---|---|---|
| 02 Sep | Run completed | CF-2026-0184 | R. Okafor | Verified |
| 02 Sep | Client share created | CF-2026-0184 | R. Okafor | Verified |
| 01 Sep | Conflict check | CF-2026-0190 | System | Needs a check |
One audit register row for a run, a share and a conflict check.
6
families of event in one register: runs, verification, shares, documents, members, conflict checks.
4
outcomes a row can carry: ok, attention, failed, info.
SHA-256
content digest over every row in a printed inspection bundle.
Six families of event, one shape
Agent runs, verification checks, share links, documents, members and conflict checks each read as a plain-English line with one of four outcomes. 'Attention' is not a soft failure: it means the work completed and a check on it did not pass, and that row earns its own level rather than hiding inside 'ok'.
Read the verification page| Date | Event | Matter | Actor | Result |
|---|---|---|---|---|
| 02 Sep | Run completed | CF-2026-0184 | R. Okafor | Verified |
| 02 Sep | Client share created | CF-2026-0184 | R. Okafor | Verified |
| 01 Sep | Conflict check | CF-2026-0190 | System | Needs a check |
Four example rows, one per outcome.
Derived from the work, not written alongside it
There is no separate audit table maintained in parallel. The register is projected from the rows that already record the truth, so it cannot quietly disagree with the runs, checks and share links it describes.
Read the security statement| Date | Event | Matter | Actor | Result |
|---|---|---|---|---|
| 02 Sep | Run completed | CF-2026-0184 | R. Okafor | Verified |
| 02 Sep | Client share created | CF-2026-0184 | R. Okafor | Verified |
| 01 Sep | Conflict check | CF-2026-0190 | System | Needs a check |
Six source tables feeding one chronological register.
A file to analyse, a file to hand over
CSV export for anyone who wants to sort it. An inspection bundle is self-contained HTML you print to PDF: a cover page with the firm, the period and the totals, events grouped by matter, and a content digest: a SHA-256 over the exact rows exported. It is a content digest, not a tamper-evident hash chain, and the bundle says exactly that.
Book a 20-minute walkthrough| Date | Event | Matter | Actor | Result |
|---|---|---|---|---|
| 02 Sep | Run completed | CF-2026-0184 | R. Okafor | Verified |
| 02 Sep | Client share created | CF-2026-0184 | R. Okafor | Verified |
| 01 Sep | Conflict check | CF-2026-0190 | System | Needs a check |
The inspection bundle's cover page and content digest.
How it works
- 01
Work happens
A run, a share, a conflict check: the operational record is written once.
- 02
The register projects from it
Six families of event, one plain-English line each, with an outcome.
- 03
Export or print
CSV for analysis, or a printable inspection bundle with a content digest.
- 04
The hold policy, if switched on
A failed authority holds work until an owner overrides it, with a note.
What it does not do
- The content digest is a SHA-256 over the exported rows, not a tamper-evident hash chain, and the bundle does not claim to be one.
- The register is in the product on every plan; exportable audit logs and retention controls are on Business.
- This is a conflict check with restricted-matter redaction, not an ethical wall or an information barrier.
Questions this page provokes
Take the inspection bundle to your risk committee.
Twenty minutes, and we will generate one on a demo firm so you can see the format first.