Governance Control Plane
Every governed action, human-approved and cryptographically verifiable
—
Actions under governance
all time
—
Human-approval rate
of decided actions
—
Activity this month
September 2026
Unverified
Chain integrity
click Verify to re-hash
Verify chain integrity
Approval-first by design: the AI classifies intent and is air-gapped from execution. Every governed action requires an explicit human approve or deny decision before anything runs, and each decision is appended to an append-only, tamper-evident SHA-256 chain. Nothing in this plane can mutate the chain or bypass approval. You can re-hash the entire chain yourself, and re-verify the exported CSV offline, without trusting AscendCore.
Compliance evidence export
Export the full tamper-evident audit chain as a CSV your auditor can independently re-verify. Each row carries its SHA-256 and the prior row's hash, so completeness and integrity are provable offline.
Controls this audit chain provides evidence for
- Evidence for: SOC 2 CC7.2 / CC7.3 (system monitoring, change detection). Every governed action is recorded append-only with actor, target, and timestamp.
- Evidence for: SOC 2 CC8.1 (change management). Each change carries an explicit human approve or deny decision.
- Evidence for: SOC 2 CC6.1 (logical access). Actor identity is bound into every record's hash.
- Evidence for: ISO 27001 A.12.4 (logging and monitoring). The chain is cryptographically verifiable end to end.
SOC 2 Type I is planned (about a 90-day window once enrollment begins). AscendCore is not currently SOC-2 certified or in assessment. This export is evidence you can hand your auditor, not a SOC-2 report.
Every row carries its sequence number, actor, action, target, SHA-256 hashes, and a mode tag (live or sandbox) in the final column, so an auditor can re-verify the full chain offline and filter out training runs. A one-click production-only export ships in a later release.
Oversight evidence pack
A window of the live audit chain compiled into an auditor-ready artifact: what was proposed, what a named human decided, what executed, and the controls it is evidence for. CSV and print-exact PDF; sandbox events are excluded by query.
- Evidence for: SOC 2 CC8.1 (change management). Each governed change in the window carries a request, an explicit human decision, and an execution outcome as chained events.
- Evidence for: SOC 2 CC6.1 (logical access). Decision rows carry the approving surface identity; the pack measures the share of decisions with a named approver rather than asserting one.
- Evidence for: SOC 2 CC7.2 / CC7.3 (monitoring and change detection). The listing is drawn from the append-only SHA-256 chain and every row is offline re-verifiable.
- Evidence for: documented human oversight of AI-agent-initiated actions. Agent proposals and human decisions are recorded as separate chained events, so oversight is demonstrable per action.
Last 30 days of live events. Without the render service configured, the PDF button opens a print-exact page in a new tab instead.
Signals
Detections from Microsoft Entra ID Protection and Okta ThreatInsight become containment proposals with a human approval in front of every action. The detection source is named on every card, and nothing auto-contains: an approver decides, the runbook executes, the chain records detection, decision, and outcome.
Loading signal activity…
Countersigned evidence
Nightly checkpoints commit the audit chain to an independent RFC 3161 timestamp authority. History covered by a checkpoint cannot be silently rewritten afterward, by anyone, including AscendCore. Entries newer than the latest checkpoint are countersigned on the next sweep. You can verify a checkpoint yourself with standard tools; no trust in AscendCore is required.
Loading checkpoint status…
Planning a SOC 2 or ISO assessment, or need real-time SIEM streaming?
Splunk HEC and Microsoft Sentinel streaming, scheduled evidence pulls, and a production-only export ship in a later release. Tell us your audit timeline.