Evidence and accountability for consequential AI agentsBeta

Evidence for every consequential action an AI agent takes.

Subra binds each consequential action to the identity presented, the organisation, the accountable owner, the declared scope, and the policy and model versions in force - then produces signed evidence that can be checked independently later, by someone else.

UK / EU data residencyNever in your agents’ runtime pathSigned, versioned, permanently held
One identifierMultiple signed versions

Every version it has ever had.

The identifier never changes. The scope and the accountable role do. Earlier versions are kept, so what the agent was allowed to do last March is still answerable.

Subra

Portable agent identity

One registry. A distinct passport for every agent.

Move through signed identity records for operational agents. Each card keeps ownership, declared scope and a permanent AIN bound together.

Payments Operations Agent selected

Subra
Lifecycle activePayments Operations AgentAccountable ownerPayments Operationspayments.initiatePermanent AIN01AR Z3ND EKTS V4RR
Subra
Lifecycle activeCustomer Communications AgentAccountable ownerCustomer Experiencecustomer_comms.sendPermanent AIN01CS 8JH4 Q2YM 6N7P
Subra
Lifecycle activeVendor Risk Review AgentAccountable ownerRisk & Assurancevendor_risk.reviewPermanent AIN01VR 7QPA 19DM 8K2L
The problem

When an agent action has to be explained, the evidence is rarely in one place.

Identity, authority, ownership, policy and model versions often live in different systems. Runtime logs show what happened, but not always what the agent was authorised to do.

  1. Identity

    Held by IAM or an agent protocol.

  2. Authority

    Stored in policies and approval records.

  3. Versions

    Model and policy versions change over time.

  4. Accountability

    Often a role maintained in a spreadsheet.

  5. Activity

    Logs show what happened, but may not prove the authority relied upon.

The unanswered question

Who acted, under whose authority, using which policy and model version?

Audit teams assemble these fragments manually after the event.

How Subra works

From external identity to independently verifiable evidence.

Subra doesn't replace the systems you already use to establish identity and authority. It sits alongside them, and turns each completed action into a signed record.

  1. Your existing identity system is trusted, not replaced

    MechanismAccepts the identity already presented via ARIA, DID/VC, OAuth/OIDC or your enterprise IAM.

    OutputAccepted identity reference
  2. The accountable person and their authority are attached

    MechanismResolves the organisation, named owner and declared scope.

    OutputBound authority context
  3. The action is recorded after it happens, not before

    MechanismCaptures the completed action and its stated intent.

    OutputAction attestation
  4. The exact policy and model version in force is locked to the record

    MechanismBinds the policy and model version snapshot at the time of action.

    OutputVersion snapshot
  5. The record is signed so tampering is detectable

    MechanismIssues a signed, tamper-evident receipt.

    OutputSigned receipt
  6. Anyone can check it later, independently

    MechanismReceipts assemble into evidence packages, re-verifiable at any later point.

    OutputVerifiable evidence package

Compatibility

Keep the identity and control systems you already trust.

ARIA, DID/VC, OAuth/OIDC and enterprise identity systems establish how an agent presents itself. Subra sits alongside that layer. It doesn't compete with it, replace it, or ask you to adopt something new in its place.

External identity and control

  • ARIA
  • DID / VC
  • OAuth / OIDC
  • Enterprise IAM

Subra

Evidence layer

  • Identity evidence
  • Accountable context
  • Action record

Independent use

  • Audit teams
  • Risk owners
  • Regulatory review
  • Does not replace your IAM
  • Does not orchestrate agents
  • Does not become a runtime gateway

The action receipt

One action. One evidence record.

Every action produces a receipt like this. Human-readable first, with the underlying cryptography available one layer down for anyone who needs to check it.

Subra

Action receipt
Signed record

Completed action

Supplier payment initiated

Stated intentSettle approved invoice INV-2048 for £18,450.00

External identity reference
Payments Operations AgentOIDC workload identity · subject payops-agent-042
Organisation
Example Payments LtdOrganisation of record
Accountable owner
Payments Operations LeadNamed operational role
Declared authority
Supplier payments up to £25,000Dual approval required
Policy version
Supplier Payments Policy · v12Version in force at occurrence
Model version
Payments Intent Model · 2026.07Version reported by the agent system
Technical proofHashes, signing key and signature state
Previous receipt hashsha256:5bc14f79d31e472bc71af26c3c8a75f3bff847e2d494597aa4fd41c690b2e118
Receipt hashsha256:8d42e58e93bf0c87c9909f7988d2e01c6ce2d7d5bc0a2d87cb2b0f617a8d09c4
Signer keykid:subra-example-receipts-2026-07
Signature state Signature validEd25519 · key active at recorded time

Evidence packages

The evidence an auditor asks for, assembled around the action.

A package brings the identity, accountability, scope, receipts, versions and verification results for a given period into one signed manifest. It is reviewable on its own, without needing access to Subra.

Request private preview

Payments operations

July 2026 evidence review

Verified package
Review outcomeEvidence assembled and independently checkable

The package connects the accountable context and versions in force to every included action receipt for the selected period.

Review period
01 to 31 July 2026
Action receipts
42 consequential actions
Accountability
3 named operational owners
Verification
All included signatures verified
Package narrative is templated, not AI-generated. No model is used to decide what a record means.

Integrity

Evidence should remain verifiable after the originating system is unavailable.

A record you can argue with is not evidence. Each receipt is linked to the one before it. Changing any field breaks the chain, visibly.

Independent chain check

Payments operations · 24 July 2026
Verified4 of 4 records intact
Record01
Identity acceptedExternal identity attached
Intact
Record02
Payment submittedAmount: £24,800
Intact
Record03
Receipt issuedAction evidence signed
Intact
Record04
Package assembledReceipt included in review
Intact

Test the evidence yourself.

Change the payment amount in record 2 and watch the verifier recalculate the chain.
Progressive disclosureHow this is calculated
01Canonicalisation

The same fields are always placed in the same order and format, so the same record always produces the same result.

02Hashing

Each formatted record is converted into a unique digital fingerprint and includes the fingerprint of the record before it.

03Signatures

The fingerprint is signed by Subra. An independent verifier can check who signed it and whether it has changed.

Verification recalculates the record. Nothing is simply trusted from storage.

Where this applies

Built for organisations where an agent's action carries a consequence.

Three examples of the high-stakes workflows Subra is designed for, organised by the action taken, not by industry vertical.

  1. 01

    Payments and refunds

    Action
    An agent initiates a refund or payment.
    Risk
    Incorrect or unauthorised transfer.
    Accountable function
    Operations
    Evidence produced
    Signed receipt showing the scope result and amount against declared limits.
  2. 02

    Lending and underwriting operations

    Action
    An agent updates or recommends within an underwriting workflow.
    Risk
    Decision made outside authorised parameters.
    Accountable function
    Credit Risk
    Evidence produced
    Receipt binding the decision to the policy version in force.
  3. 03

    Insurance claims

    Action
    An agent processes or escalates a claim.
    Risk
    Inconsistent or unauthorised claims handling.
    Accountable function
    Claims Operations
    Evidence produced
    Receipt and evidence package for claims audit review.

Thirty minutes is usually enough to see where your agents sit against this.

Security and boundaries

What Subra stores, and what it deliberately does not.

Subra is built to record the minimum evidence necessary, not to become a second copy of your operational logs.

10 checkable statementsProduct and security boundaries
Technical detailMinimum necessary evidence recorded

Subra records the identity, accountable context, action, scope result and versions needed to explain an action. Customer payloads are excluded by default.

Select any statement to inspect its boundary in context.

Frequently asked

Questions we get from compliance, risk and engineering teams.

The identity presented, the organisation, the accountable owner, the action and its intent, the declared authority and scope result, the policy and model versions in force, and a signature over the whole record.

Private preview

Be ready to explain every agent action that matters.

We're working with a limited number of regulated organisations that operate real AI-agent workflows and need stronger evidence around authority, accountability and actions.

Limited preview cohort

Use your organisation email address.

By submitting, you agree to our Privacy Notice.

Subra is not regulatory advice and is not endorsed by or affiliated with any regulator.