Overview
How might we design audit trail so people can trust and act on AI output?
When to use
- Critical for enterprise applications, regulated industries, and systems where comprehensive audit trails ensure compliance, accountability, and transparency.
When to skip
- Personal creative sandboxes with no shared accountability need.
- Throwaway prototypes where retention would create unnecessary privacy risk.
- Ultra-low-latency edges where logging every token would break the product (sample instead).
Rules
Logs that only store model text and omit tool calls or user identity.
Audit UIs readable only by engineers, with no product-facing timeline.
Immutable claims while still allowing silent admin edits to history.
Retaining raw prompts forever with no retention policy or redaction.
Evidence
| Product | Implementation |
|---|---|
| Enterprise AI platforms | Admin timelines of prompts, model versions, and actions. |
| Healthcare AI | Decision logs tied to clinician identity and patient record access. |
| Financial AI | Model-assisted decision records for regulators and internal review. |
| Compliance tools | Exportable trails of AI suggestions and human overrides. |