Black Box
The flight recorder for AI actions.
Reconstruct who requested an action, under whose authority, against which rule, with which approval, and what happened afterward.
Action recording is available only for connections that pass through SafeUs control points.
What it records
- Who authorized it
- What was requested
- Which rule applied
- Human approval, if required
- What actually happened
- Evidence status
What it never records
- Message bodies and file contents
- Raw responses from your providers
- Passwords, keys or tokens
- A score about you or your people
Recording coverage
Agents and tools that act through a SafeUs control point (MCP gateway, API gateway, edge). Each action has a decision, an outcome and an evidence state.
Accounts connected by sign-in permission (for example Google or Microsoft 365). SafeUs sees which apps hold access and can withdraw its own — it does not see each action they take.
An empty Black Box does not mean you are safe. It means no supported action passed a control point in that period.
Audit example
Illustrative record — demo data
Evidence states
- Evidence ReadyEvidence Ready — decision, outcome and proof reference are sealed.
- …Proof being prepared — the action is recorded; the seal follows. A retry never repeats the action.
- —Not executed — denied or held requests show the decision, never a fake outcome.
- Agent
- Sales agent
- Rule
- Customer export needs a person
- Approval
- Data owner · once
- Action
- Export 1 report
- Outcome
- Completed
- Evidence
- Evidence Ready
- trace
- tr-4b17…e2a9
- audit
- m10n:7c41…e2a9
- proof
- vcn:9ad2…0f62
Export the Black Box on every plan — references and hashes, never content. How long records are kept depends on your plan.