Most agent audit records can be edited after the run. The party that owns the store can append to a decision, delete one, or rewrite it, and nothing in the record shows the change happened. A record that can change after the decision it documents is a claim about the past. It is not proof of it.
Identity answers who acted. Content answers what the agent did. Both assume a third fact they do not establish. That the record in front of the examiner is the record written at the moment of the decision.
That assumption is what a hash chain exists to remove. It is also what the word hash-chained is increasingly used to gesture at in a product sheet without delivering.
What integrity actually means.
Integrity has a precise meaning here. Altering or removing any single record after it is written becomes detectable. Not prevented. Detectable. The distinction matters because prevention depends on controlling who holds the store, and the examiner is in the room because that control is the thing under review.
Hash-linkage is how detection is achieved. Each record carries a digest of its own contents. Each record's digest folds in the digest of the record before it. The records form a chain in which every link commits to the entire history behind it. Recompute the chain and compare. A single edited field anywhere in the past changes every digest from that point forward.
Integrity is the property that altering or removing any one decision after the fact becomes detectable to a party who trusts neither the vendor nor the operator.
Three nearby properties get mistaken for it. Encryption keeps the record private, and a private record can still be rewritten by whoever holds the key. Access control governs who may write, and a correct permission model still says nothing about whether what was written stayed written. A signature attests authorship, and a signature over a store whose rows can be swapped attests only to whatever sits in the store at the moment it is read.
Append-only is the claim, not the proof.
The common form of an agent audit log is append-only. New records go on the end. Existing records are not meant to change. Append-only is a configuration. The party that owns the store sets it, and the same party can unset it. An append-only log without hash-linkage is a promise the operator makes about its own future behavior.
The examiner pulls one decision precisely because the operator's promise about its own behavior is what is under review. Hash-linkage moves the guarantee from policy to arithmetic. Removing one decision from a long chain is not a quiet deletion. It rewrites every digest after it, and any retained copy of a later link, held by a counterparty, a regulator, or a notarization service, exposes the rewrite.
Hashing the input is not hashing the decision.
A system can hash the inputs it received, link those hashes, and present the result as an audit chain. The chain is real. The object it secures is the wrong one. Hashing the inputs proves what the agent saw. It is silent on what the agent decided, under which authority, and whether the action was reduced or stopped before it ran.
The object that has to sit inside the chain is the decision record. The authority in force when the agent acted. The action it proposed. The action it was permitted. The bound it was checked against, and the result of that check. A chain over the inputs and a chain over the decisions look alike on a slide. Only one of them answers the question an examiner pulls a single decision to ask.
Hashing what the agent saw secures the input. Hashing what the agent did is the part that has to be in the chain.
Why the burden moved to you.
SR 11-7 was rescinded on April 17, 2026 and replaced with SR 26-2. The new guidance carves generative and agentic AI out of scope on the grounds that the technology is moving too fast to fix in a standard, and it points institutions back at their own general risk-management practices. A forthcoming interagency RFI will take up how these systems should be governed.
When a framework names the control, the integrity of the evidence behind it is assumed. When a framework declines to name the control, the integrity of the evidence becomes a design choice the institution owns and has to defend on its own. The record-keeping and logging obligations for high-risk systems under the EU regime point the same direction. A log the operator can revise does not establish the traceability those obligations require.
The question is no longer whether a record exists. The question is whether the record can be shown to be the one written at the time, by a party who was not in the room and does not trust the party who was.
What we are building.
Wayfinder Systems Group builds one answer to the substrate question. A runtime governance layer that signs every decision and every learning event onto a tamper-evident chain at the moment it happens. Each link commits to the one before it. The decision record is the object inside the chain, not the inputs alone. A second implementation in a different language reproduces the same chain byte for byte, so the record can be verified by a party who trusts neither build. The reviewer reads exceptions. The examiner reads a record that cannot have moved since it was written. Patents held in The Wayfinder Trust. We call her Velma.
Thirty minutes. Architecture, not sales.
A conversation about what makes an agent record resist being edited after the decision, and how the chain is verified by a party who trusts neither the vendor nor the operator.
JonathanLuethke@WayfinderSystemsGroup.com
