COMPLIANCE
Compliance evidence for AI agent tool calls
Stipul does not make an organization compliant by itself. It produces structured compliance evidence for mediated AI agent tool calls routed through Writ: what was requested, which Charter rule applied, whether Writ allowed or denied the call, whether a denied call was forwarded, and whether the Chronicle evidence remains intact.
What this page claims
This page maps Stipul to compliance control themes. It is not legal advice, an audit opinion, a certification claim, or a guarantee of regulatory compliance. Stipul can help produce evidence that may support governance, risk, compliance, and audit workflows when AI agent systems execute business-critical mediated tool calls through Writ.
Control themes Stipul supports for AI agent compliance
Runtime authorization
Stipul enforces the Charter before mediated tool calls execute.
Least privilege for tool execution
Charters can limit tools, parameters, destinations, workflows, and high-risk actions.
Denied-call evidence
Chronicle records denied mediated calls and the rule that triggered the denial. Writ does not forward denied calls through the governed path.
Tamper-evident evidence
Chronicle records mediated enforcement decisions as a hash-chained evidence sequence. Seal verifies whether the evidence remains intact.
Policy accountability
Charter fingerprints tie evidence back to the policy in force for the session.
Boundary disclosure
Stipul explicitly defines what it does not control: direct API access, leaked credentials, compromised hosts, unmanaged SDK calls, and paths outside Writ.
How Stipul maps to compliance frameworks
AI agent threat model facts that matter for compliance
Assets Stipul helps govern
- Charter policy artifacts
- Writ enforcement decisions
- Chronicle evidence chain
- Seal verification receipts
- Session context
- Downstream tool execution path
Actors in scope
- Operator configuring Charters
- Agent requesting mediated tool calls
- Writ enforcing policy
- Third-party API receiving allowed calls
- Verifier checking evidence integrity
- Attacker attempting to bypass, tamper, or misrepresent evidence
Primary threats Stipul addresses
- Unauthorized mediated tool call
- Dangerous action denied before execution
- Denied call falsely claimed as forwarded or not forwarded
- Evidence tampering after the session
- Charter mismatch or policy drift
- Misleading audit trail assembled after the fact
Threats Stipul does not address by itself
- Direct API access outside Writ
- Leaked credentials used outside the governed workflow
- Compromised host running Writ or the agent
- Incorrect Charter policy
- Deleted or non-durable evidence stores
- Third-party API state changes after an allowed forwarded call
- Channels not integrated with Writ
Compliance evidence artifacts Stipul can produce for AI agent audits
Charter fingerprint
Shows which policy was in force.
Decision record
Shows requested tool, applied rule, decision, timestamp, and session context.
Forwarding status
Shows whether a mediated call was forwarded through Writ.
Chronicle hash chain
Shows whether the recorded sequence remains intact.
Seal receipt
Shows whether verification returns VERIFIED or REJECTED.
Boundary statement
Shows what Stipul does not claim to control.
Roadmap items, not current claims
Credential custody
Production deployments need a hardened model where downstream platform credentials live behind Writ, not inside the agent runtime.
Bypass prevention
Enterprises need deployment controls that reduce unmanaged paths around Writ.
Evidence durability
Chronicle integrity can be verified, but evidence storage durability and retention are deployment responsibilities until stronger managed storage exists.
Origin binding
Current verification proves evidence integrity under Stipul's trust model. Stronger enterprise identity binding and signing-key custody remain roadmap items.
Charter validation
Stipul enforces the Charter as written. Tooling to test and validate Charter intent remains roadmap work.
Security reporting
Security issues that affect Stipul's enforcement boundary, denied-call forwarding behavior, Chronicle evidence integrity, Seal verification, secret handling, or public claims can be reported to [email protected].
- affected version or commit SHA
- reproduction steps
- expected behavior
- actual behavior
- impact
- suggested mitigation if available
What Stipul does not do for compliance
- Does not make legal compliance determinations.
- Does not certify AI systems.
- Does not classify systems under the EU AI Act.
- Does not validate whether a Charter is legally sufficient.
- Does not assess model fairness, bias, or explainability.
- Does not protect direct API access that bypasses Writ.
- Does not protect leaked credentials used outside the governed workflow.
- Does not replace IAM, GRC, SIEM, endpoint security, host security, or audit procedures.
Why this matters
Enterprises do not only need agents to act. They need evidence that governed actions were authorized, denied, recorded, and verifiable. Stipul creates a deterministic control and evidence layer for mediated AI agent tool calls, with explicit limits around the path it governs.