crossbearingagent evidence

What your AI agents did
vs. what they said

A read-only evidence engine in your own cloud account. It corroborates what your agents claim against the records your infrastructure already keeps — AWS, GCP, Azure, Kubernetes, GitHub — and surfaces the divergence as auditor-ready, signed evidence.

Nothing installs in the agent path. One read-only role connects it.

position fix
3 bearings
records crossing

three bearings — a position fix. Toggle a stream to add or drop a bearing.

the principle

A navigator never trusts one bearing. Neither should you trust the claim alone.

A cross bearing fixes a position from independent reference lines: no single line is enough, but where several cross, the true position is pinned. crossbearing does the same with your agents — it crosses what an agent says it did against the records your clouds keep anyway.

claim

What the agent says it did — its own telemetry, receipts, tool logs, CI output.

record

What your infrastructure actually logged — AWS, GCP, Azure, Kubernetes, GitHub.

divergence

Where the two disagree — an action with no claim, a claim with no record, a human nobody can name.

the reference lines

Five record streams, validated against real data. Each is a bearing.

AWS is the live bearing — read live from your own account and signed with your own KMS key. GCP, Azure, Kubernetes, and GitHub corroborate from the audit logs they already keep.

the divergence report

One agent session against AWS — and every way the story can diverge.

The agent claimed a handful of read-only calls. CloudTrail tells the fuller story: a write where it claimed a read, a production bucket it never mentioned that no human owns — pinned to the agent’s own proven credential — plus a call that left no record, and one it never claimed. The real engine, run offline.

crossbearing report — aws · cloudtrail · offline
how to read this report
corroboratedmismatchunclaimedunrecordedunattributed → agent-suspect
what one bearing can’t see
k8s audit
get secret grafana-external-credentials
05:11:16Z · arn:aws:sts::111122223333:assumed-role/AWSReservedSSO_Admin…/sysadmin
corroborated — the agent said it read the token
2 minutes — the token leaves Kubernetes, and nothing in the cluster sees what it does next
cloudtrail
grafana:delete
05:13:23Z · SAMLUser/terraform
unclaimed — no agent claim accounts for it

Neither line is a finding alone. The agent announced the read; the delete is the Grafana service account doing what it does all day. Only crossing the bearings connects them — and whether it was wrong is your call, not ours.

Two records. Two audit planes. No shared principal, credential or ARN.

the evidence package

Signed with your key. Hash-chained. Verifiable without us.

genesis
anchor · window+policy
CC6.1 · attribution
7f3a…91c4
CC7.2 · monitoring
b2e0…4d77
CC8.1 · change
c9a1…0e35
signedECDSA · your KMS key

Each link is sha256(prev ‖ finding). Edit, reorder, or drop one finding and every hash downstream changes — and the signature no longer verifies.

Re-fetchable

Every finding points at the raw event it came from, with a digest — evidence an auditor re-derives, never an assertion.

Tamper-evident

Findings are hash-chained and signed with your own KMS key. Edit, reorder, or remove one and the chain breaks visibly.

Independently verified

A separate, MIT-licensed, zero-dependency verifier checks the chain and signature offline — mapped to SOC 2 controls.

design partners

If your customers are asking what your AI agents are allowed to do, we should talk.

We are taking a small number of design partners — AI-product teams under SOC 2 / ISO 42001 pressure. You bring the agents and the clouds; we bring the evidence.