Execution evidence

What can be reconstructed after an AI execution.

Logs typically record events. Guardrails typically record enforcement. Routers typically record the destination. Kordane’s core design combines these records into one decision model: the complete reasoning context behind each execution. What that covers, by category and current state:

Kordane Boundary · Decision recordKDR-2026-0714-00381

Summarisation of a restricted investigation report was permitted in the private VPC using the specialised private model, which cleared the 0.92 quality threshold. Protected identifiers were tokenised locally before the crossing. The approved frontier route is held as fallback only.

Task
Summarise a restricted investigation report
Information class
Restricted
Requested by
Named analyst with authorised case access
Policy version
boundary-policy-17
Permitted environments
Private VPC · isolated local
Rejected environment
Public frontier API, refused for this information class
Quality threshold
F1 at or above 0.92 on the case-summary evaluation set
Transformation
Protected identifiers tokenised locally
Fallback condition
Candidate evaluation falls below 0.92 before deployment or during scheduled re-evaluation; escalation runs through the approved frontier route, after transformation
Human approval
Not required for summarisation · required before any external action

Candidate models

  • local-small-v3rejectedF1 0.89 · Below the 0.92 threshold
  • specialised-private-v2selectedF1 0.94 · Smallest permitted model above threshold
  • approved-frontierfallbackF1 0.96 · Held as fallback; not required

Evidence retained

  • Policy decision
  • Information classification
  • Transformation record
  • Evaluation set version
  • Candidate comparison
  • Selection reason
  • Fallback path
  • Response provenance
  • Decision identifier

Synthetic example · Illustrative decision record · Not customer evidence · Not a measured production benchmark

The evidence model

Six categories. One decision.

Each category below lists what the record covers and its current state, using the standard maturity vocabulary.

Task evidence

  • Task class and workflowAvailable in pilots
  • User or service identity and roleAvailable in pilots
  • Requested actionAvailable in pilots
  • Timestamp and decision identifierDemonstrated

Information evidence

  • Information classificationDemonstrated
  • Sensitive values detectedDemonstrated
  • Transformation performedDemonstrated
  • Restoration rulesDemonstrated
  • External transfer decisionDemonstrated
  • Retention ruleAvailable in pilots

Policy evidence

  • Policy version and applicable ruleAvailable in pilots
  • Permitted and rejected environmentsDemonstrated
  • Required approvalDemonstrated
  • Refusal reason where applicableDemonstrated

Model evidence

  • Candidate models and evaluation versionAvailable in pilots
  • Required threshold and measured resultAvailable in pilots
  • Selected model and rejected alternativesAvailable in pilots
  • Selection reasonAvailable in pilots

Execution evidence

  • Final route and runtimeDemonstrated
  • Tool permissionsAvailable in pilots
  • Human approval recordAvailable in pilots
  • Fallback condition and any fallback usedAvailable in pilots
  • Output provenanceAvailable in pilots

Review evidence

  • Export for reviewAvailable in pilots
  • Retention controlsAvailable in pilots
  • Reviewer and review statePlanned
  • Replay and reconstructionPlanned
  • Integrity controlsPlanned

Statuses use the standard maturity vocabulary. Evidence is not presented as immutable, cryptographically verifiable or legally certified; integrity and replay are on the roadmap and labelled planned.

Three controlled workflows

Where the decision materially matters.

Synthetic walkthroughs · Illustrative policy and evaluation values

Restricted document analysis

Sensitive input
A restricted investigation report enters locally.
Policy question
May this content cross, and in what form?
Permitted environment
Private VPC or isolated local; the public frontier route is refused for this class.
Model threshold
F1 at or above 0.92 on the case-summary evaluation set
Selected route
Specialised private model
Fallback
Approved frontier after tokenisation, only if the evaluation gate fails
Evidence produced
Classification, transformation, candidate comparison, selection reason, provenance
See the product →

Regulated customer response

Sensitive input
Customer information retrieved under role policy.
Policy question
Which environment may draft this, and who must approve the action?
Permitted environment
Depends on the information class; consequential actions are gated.
Model threshold
Task-specific quality and tone criteria
Selected route
Permitted assistant model for the class
Fallback
Human handling whenever policy or the threshold requires it
Evidence produced
Role policy, environment decision, approval record, response provenance
See the product →

Sensitive audio processing

Sensitive input
Audio that may not leave the environment.
Policy question
Must transcription and extraction stay local?
Permitted environment
On-premises or isolated; external escalation only where policy allows.
Model threshold
Language-specific transcription and extraction criteria
Selected route
Local transcription, then a permitted specialist model
Fallback
External escalation only after transformation, and only if permitted
Evidence produced
Transformation record, model choice, output provenance
See the product →

Discuss one workflowSee a controlled crossing