Under whose authority, at what cost, and be able to pause or roll it back, with evidence. AskLedger gives every production agent a stable machine identity and a named human owner, keeps its capabilities inside pre-approved limits, and records a signed receipt for every action it attempts and every action it executes.
Autonomy without accountability is a liability. The control model keeps an agent's blast radius small, its authority explicit, and its runtime behavior tied back to the decisions and configurations that permitted it.
Every production agent has a stable machine identity and a named human owner accountable for it.
Tools, data classes, jurisdictions and spending limits are approved before the agent runs.
Policy is evaluated before sensitive actions, with attempted and executed events recorded separately.
Short-lived credentials and least privilege keep the blast radius of any single agent small.
Escalation, pause, revocation, rollback and kill-switch controls are tested and evidenced, never assumed.
Runtime activity links to evaluation results, versioned configurations and downstream outcomes.
From the moment a task is assigned to the moment it's completed, or rolled back, each step emits a receipt or evidence event, so the full story of what the agent did is reconstructable and verifiable.
Requester, purpose, agent identity and approved use case.
Plan hash, tools anticipated and the policy version in force.
Target resource, requested scope and the policy decision.
Result, changed resource, cost and the execution identity.
Reviewer, decision, and any exception or override.
Outcome, quality signal and business reference.
Control invoked, its result and the recovery state.
AskLedger doesn't invent a parallel agent stack. It captures interaction metadata from the protocols agents use to talk to tools and to each other, and relies on your existing workload identity patterns where possible.
Supports Model Context Protocol interaction metadata: tool requests, policy decisions and execution results captured as agents call their tools.
Captures agent-to-agent interaction metadata, so multi-agent handoffs stay attributable across the chain.
This aligns with emerging guidance that emphasizes agent ownership, inventory, identity, observability, data controls and standard protocols such as MCP and A2A, layered onto workload identity you already run rather than a new identity system.
An agent that can act on your systems needs the same accountability you'd demand of a person with those permissions: an owner, approved limits, a record of what it did, and a way to stop and undo it. AskLedger makes that record signed and independently verifiable, so the answer to "what did the agent do, and who authorized it?" survives an audit.
AskLedger is at design-partner stage. The agent accountability workspace described here is on our roadmap; we're building it now with a small set of design partners.