02How to
How do you tell if an AI agent did what it said?
Do not ask the agent. Check the record held by the system that received the work.
An agent's own log, summary or status says what the agent believes happened. The receiving system's record shows what actually arrived. If you cannot check that record, the honest answer is unknown, not done.
7 steps
- List what the agent can touch. Every action it is deployed to take: wire funds, change records, bind coverage, grant access, delete data.
- Decide before it runs what is cleared. Who or what may allow each action, under what limits, and which actions need a person.
- Get an answer before the action, not a story after it. Allow, deny or escalate, recorded somewhere the agent cannot edit.
- Record the exact details that were judged: which agent, what action, what target, which arguments.
- After the action, check the receiving system's own record. Not the agent's report.
- Report 3 outcomes, not 2: found, not found, could not check. Treat could not check as unknown. An outcome we cannot confirm is reported as unknown, never as success.
- Keep the records where the person who has to say yes can open them.
4 mistakes that look like proof
- Trusting the agent's summary. It describes the agent's belief, not the receiving system's state.
- Reading the absence of an error as success. Silence is not a result.
- Reading no record as proof it did not happen. It may mean you could not check. Keep 'could not check' apart from 'checked and found nothing'.
- Keeping the only evidence in the agent's own tools. The party under review should not be the only witness.
Where TrustGate fits
TrustGate covers steps 2 to 6 for actions that go through it. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. The receipt binds the agent, action, target and exact arguments that were evaluated.
TrustGate reports 'could not check' separately from 'checked and found nothing'.
To see the 3 answers, hand the demo a decision. It is simulated and uses made-up data.
What this is not
These steps give you evidence, not a lock. Signatures prove and detect. They do not prevent. They do not make a workflow compliant, and they do not catch every failure.
Quick answers
How do you tell if an AI agent did what it said?
Do not ask the agent. Check the record held by the system that received the work. If you cannot check it, the honest answer is unknown, not done.
Why is an agent's own log not enough?
The agent, or a tool that only watches the agent, wrote it. It records what the agent believes happened, not what the receiving system holds.
What is the difference between 'not found' and 'could not check'?
Not found means you looked and the record is not there. Could not check means you could not reach the record. They mean different things, so report them apart.