The scenario

Your AI agent just deleted a customer record. Three months later, an auditor asks you to prove:

What tool actually ran (not "the agent made a deletion call" — the precise tool, version, and capability)

With what arguments (the exact customer ID, scoped fields, options — byte-for-byte)

Who approved it (which human, or which automated policy rule)