Governance You Can Show Someone Else

Controls only count if you can show them working. Three records answer the questions a reviewer asks: who changed what, who approved it, and what the agent actually did.

Cloptima TeamOctober 5, 2026 9 min read
In this post
  1. 01The question after the incident
  2. 02Three records, three questions
  3. 03What changed, and who changed it
  4. 04Who approved it
  5. 05What the agent did
  6. 06You choose how much to keep
  7. 07A Monday morning, answered in minutes
  8. 08What reviewers ask for
  9. 09Evidence is not compliance
  10. 10A review you can run in an hour
  11. 11Your first week

The question after the incident

Every incident review reaches the same three questions, and they are rarely asked kindly.

Picture this

A model bill doubles over a weekend. On Monday a manager asks: what changed, who allowed it, and what did the agent do? If the answers live in three people's memories and a chat thread, the review turns into a debate. If they live in records, it turns into a fix.

Having controls is the first half of governance. Being able to show them working is the second.

Three records, three questions

Cloptima keeps one record for each question.

QuestionRecordWhere
What changed, and who changed it?The Control Plane Audit LogAI → Audit
Who approved the risky ones?The Approval queue and its decisionsAI → Audit
What did the agent actually do?Session tracesAI → Sessions

Each is written as things happen, not reconstructed afterwards.

What changed, and who changed it

Changes to your gateway are recorded with the person, the time, and the target.

  • Policies and bindings: created, updated, deleted
  • Virtual keys: created, updated, rotated, revoked
  • Provider credentials: created, validated, rotated, revoked
  • Tool servers, guardrail profiles, edge instances, and cache invalidations

You can filter by action, search by name, and export the log for a review.

Who approved it

Some changes can raise cost or risk, so they ask for approval before they take effect.

ChangeAsks for approval
Raising a budgetYes
Allowing a costlier modelYes
Activating a tool serverYes
Switching the semantic cache to EnforceYes
Lowering a budget or removing a modelNever

A reviewer approves or rejects with a note. Someone below admin cannot clear their own request. An admin who needs to move fast can apply a change immediately, and the self-approval is recorded.

What the agent did

Session traces turn an agent run into a readable sequence.

  • Every request in the session, in order, with model, cost, and status
  • The tools it called, with arguments and results, if you choose to keep them
  • A verification state on each record, so you know it is intact

A log you cannot verify is a story. A log with a fingerprint is evidence.

You choose how much to keep

Privacy and evidence pull in opposite directions.

The policy lets you choose where to stand.

ModeKeeps
Zero retentionCounts and cost only. The default
Attribution onlyLabels, metrics, and tool names
Tool callsTool arguments and results
Full auditThe text of every step

A Monday morning, answered in minutes

Return to the doubled bill. With the three records, the review goes like this.

  1. 1

    What changed

    The Control Plane Audit Log shows a policy update on Friday at 17:12 that raised the daily budget and added a model.

  2. 2

    Who approved it

    The Approval queue shows the request and an admin's approval with a note: temporary for a launch.

  3. 3

    What the agent did

    The session view shows one run that repeated the same tool call sixty times over the weekend.

Three different causes were in play: a loosened limit, an approved change, and a looping agent. Without the records they blur into one argument. With them, each gets its own fix.

What reviewers ask for

Auditors and security reviewers ask for the same kinds of evidence again and again.

They askYou show
Who can change AI settings?Owner and admin roles, and the audit log of their changes
How are risky changes controlled?The approval types and the decisions in the queue
Can you reconstruct an agent's actions?A session trace with a verified record
Is sensitive data kept?Your retention mode, and the guardrails that run before storage
How do you respond to an incident?The path from Explorer to Audit to Sessions

Evidence is not compliance

Be honest about what records prove.

These records help you document and run your own controls. They do not make you compliant with any standard on their own. They give your auditors something concrete to examine, which is usually where an audit gets easier.

A review you can run in an hour

A short, regular review keeps the records useful.

  1. 1

    Approval queue

    Clear anything pending, with a reason.

  2. 2

    Policy Violations

    Read the top groups and fix any that block real work.

  3. 3

    Control Plane Audit Log

    Scan policy, key, and credential changes for surprises.

  4. 4

    Sessions

    Open the most expensive agent session and read it.

  5. 5

    Export

    Save the log for the month.

Your first week

Start with the records you can turn on today.

  • Open the Audit tab and read each card once
  • Name your reviewers for risky changes
  • Choose Tool calls retention for one agent policy
  • Put the Audit tab on your on-call checklist
  • Run the review above at the end of the week
Put it into practiceRead the audit log and prove who changed whatUse the Audit tab to answer who changed a policy and why a request was blocked.

Keep reading

Ready to Try Cloptima?

Bring LLM FinOps, governed model access, and cloud cost optimization into one operating model.

No credit card required
5-minute setup
Free trial