Platform · Prove
Every decision,
with the reason
attached.
What was allowed, warned on or blocked. Why. And which policy applied, at which revision.
The point
A decision you cannot explain is a decision you cannot defend. Not to an auditor, not to a customer, and not to the engineer who wants to know why their agent stopped.
Anatomy of a decision record
What gets recorded.
The same shape every time, so reconstructing what happened is reading rather than detective work.
Provenance
Who changed a control, and when.
Every publish is a numbered revision with a name on it. Read the diff between any two, or restore an earlier one.
- Nothing changes quietly.
- Changing a control is an event with a name attached, not a setting somebody moved.
- Warn on bulk-export · Skill
- 17 rules unchanged
Published by your security team.
Scope
One record, read at three distances.
The same decisions roll up from a session to a person to the organization. Nothing is re-derived on the way.
One session
What this agent did, and every decision that applied to it.
One person
Their sessions over time, and what kept coming up.
The organization
The same decisions, triaged by severity.
For GRC and compliance
Controls have owners, versions, and a record of who confirmed them. Every decision carries the revision that produced it, and exports exist to support compliance work, investigations and customer assurance. “To support” is deliberate. Backplanes produces the evidence. Your program does the rest.
Next
The record is the part you will need later.
Nobody asks for a decision record on the day the decision is made. They ask three months afterwards, when it matters.