The scenario
Your AI agent just deleted a customer record. Three months later, an auditor asks you to prove:
What tool actually ran (not "the agent made a deletion call" — the precise tool, version, and capability)
With what arguments (the exact customer ID, scoped fields, options — byte-for-byte)
Who approved it (which human, or which automated policy rule)










