Problems/01

Answer an audit with records, not with a reconstruction.

Every call carries the policy that governed it, the controls that ran and the decision each one made, written at the moment it happened rather than assembled from logs six months later.

The problemAI evidence debt

AI evidence debt accumulates when you deploy AI faster than you capture verifiable proof of the policies, approvals and controls behind every action.

Inspect an evidence record All problems
Where it becomes visible

Nobody discovers this problem in a planning meeting

Security review

A reviewer asks which policy was in force for a request from March.

Customer questionnaire

An enterprise buyer wants control evidence, not a description of intent.

Regulator inquiry

A supervisory authority asks for records of processing decisions, per request.

Internal audit

Sampling picks 30 requests and expects the same artefact for each one.

Production incident

You need the call chain and the approvals behind an action that already happened.

Model or provider change

The control set moved, and last quarter of evidence no longer matches the config.

What it costs

The bill arrives as delay, not as an incident

01Rollout is blocked

Deployment waits on evidence that has to be assembled by hand.

02Deals take longer

Security questionnaires add weeks to every enterprise cycle.

03Compliance reconstructs history

Someone rebuilds what happened from logs, tickets and screenshots.

04Engineering runs manual exports

Platform time goes into one-off queries instead of product.

05The decision owner is unknown

Nobody can name who approved the behaviour that shipped.

Why the usual tooling does not close it

The gap

How obstruo closes it

The control

Logs record the request, not the policy version that governed it.
The policy version is pinned to the request and stored with it.
Approvals live in tickets, disconnected from the action they permitted.
Every approval is linked to the action it allows, with owner, scope and expiry.
Provider logs show one hop, not the agent, tool and retrieval chain around it.
The full call chain is kept as one linked record, from agent to tool to provider.
The log store is editable, so its contents are testimony rather than evidence.
Records are append-only and hash-chained, so tampering is detectable.
Framework mapping is written after the fact, once per audit cycle.
Controls carry their EU AI Act, GDPR, ISO 27001 and SOC 2 references at enforcement time.
The evidence artefact

One record per request, created while the request is being governed.

This is the shape of the record obstruo produces. It is the same artefact a reviewer, an auditor and an enterprise buyer each ask for, and it exists before they ask.

Append-only Owner named Exportable
Evidence record SEALED
Recordevt_9f3c21a7
Requestreq_8814b2 · 2026-07-14 09:41:02 UTC
Project, agentclaims-automation, claims-triage
Accountable ownerR. Nowak, claims platform
Policy versioneu-pii-strict v14, in force from 2026-06-02
Decisionallowed, redacted
Redactions4 entities: PERSON, IBAN, PAN, EMAIL
Routeobstruo-chat-eu to eu-central, no fallback used
Approvalapr_2291, no open exception
Integritysha256 chain, previous evt_9f3c21a6
MAPPED TO
EU AI Act, Article 12 GDPR, Article 32 ISO 27001, A.8.16 SOC 2, CC6.1
Written at enforcement time, not assembled at audit time. Exportable per project, agent, framework or date range.
The other three

They arrive together, and the same controls answer them

02
Agent authority drift
Read the problem page
03
Policy deployment gap
Read the problem page
04
Live processor blindness
Read the problem page

Your AI. Your data. Your control.

Bring one request your last security review asked about. We will show the record obstruo would have produced for it.

Inspect an evidence record See pricing