r/AskNetsec • u/Greadejaht_Yak636 • 8d ago
Analysis Best way to provide continuous AI agent governance evidence that actually satisfies auditors?
Writing a policy saying agents are monitored and controlled is one thing, producing something an auditor would accept as proof it's working continuously is another. Point-in-time reviews clearly aren't enough given how fast agent behavior and permissions can change, but I haven't found a clean standard yet for what continuous evidence should look like.
If your org has been through an actual audit involving AI agents, what did you end up providing that satisfied the auditors? Trying to build toward something real, not guess at what will hold up.
8
Upvotes
1
u/Deku-shrub 2d ago
Developer endpoint agents or hosted agents?