Resources · Guide

Decision receipts: auditing what an AI did on your program

Tymeline · · 3 min read

In short

A decision receipt is a signed, tamper-evident record of one consequential action by an AI: what it was asked to achieve, what it read, how it reasoned, which policy applied, and which person approved it. It turns an audit from weeks of reconstruction into a lookup.

What should a receipt contain?

Six things:

  • Intent: the goal and constraints it was working to.
  • Sources: the data it read, down to the specific run or report.
  • Reasoning: the options considered and why one was chosen.
  • Policy: the rule that applied, such as which decisions need a vice president's approval.
  • Approval: the named person, verified with MFA, and the time.
  • Provenance: a hash that shows the record has not been altered.

Why does “tamper-evident” matter?

An audit trail that can be edited is a narrative. A record that is hashed and anchored when it is written can be checked later, by someone who does not have to trust whoever kept it.

Where should it go?

Into the security tools you already run. Tymeline anchors each receipt on Tymeline ID and exports to Splunk, Sentinel and Chronicle.

See a slip caught on a program like yours.

45 minutes. No slide deck.

Independently attested. Renewed annually.