Skip to main content
SafeUs
Menu

Black Box

The flight recorder for AI actions.

Reconstruct who requested an action, under whose authority, against which rule, with which approval, and what happened afterward.

Action recording is available only for connections that pass through SafeUs control points.

What it records

  • Who authorized it
  • What was requested
  • Which rule applied
  • Human approval, if required
  • What actually happened
  • Evidence status

What it never records

  • Message bodies and file contents
  • Raw responses from your providers
  • Passwords, keys or tokens
  • A score about you or your people

Recording coverage

Action recorded

Agents and tools that act through a SafeUs control point (MCP gateway, API gateway, edge). Each action has a decision, an outcome and an evidence state.

Access visibility only

Accounts connected by sign-in permission (for example Google or Microsoft 365). SafeUs sees which apps hold access and can withdraw its own — it does not see each action they take.

An empty Black Box does not mean you are safe. It means no supported action passed a control point in that period.

Audit example

Illustrative record — demo data

Evidence states

  • Evidence ReadyEvidence Ready — decision, outcome and proof reference are sealed.
  • …Proof being prepared — the action is recorded; the seal follows. A retry never repeats the action.
  • —Not executed — denied or held requests show the decision, never a fake outcome.
Audit example
Agent
Sales agent
Rule
Customer export needs a person
Approval
Data owner · once
Action
Export 1 report
Outcome
Completed
Evidence
Evidence Ready
trace
tr-4b17…e2a9
audit
m10n:7c41…e2a9
proof
vcn:9ad2…0f62

Export the Black Box on every plan — references and hashes, never content. How long records are kept depends on your plan.

Black Box — SafeUs