Skip to content

Evidence for agent-caused production change.

Novyx gives teams a record of what the agent asked to do, what it could affect, who approved it, what ran, and how to recover.

Trust is not a dashboard full of traces.

For production-changing agents, trust means answering operational questions after something happens: which action was requested, why did it run, who approved it, what changed, and what recovery path was available?

Novyx records that evidence at the point of control, before the action reaches the underlying tool.

Live proof
108,277
audit chains verified, across all prod tenants
updates every 15s
last check
Every entry above is append-only, SHA-256 chained to the previous entry, and verifiable after the fact. The number ticks up because real agents are running through Novyx right now.

Evidence model

What every protected action should leave behind

01

Original request

The exact action the agent wanted to run, including connector, operation, payload, and stated intent.

02

Blast radius

Affected systems, records, jobs, customers, environments, and irreversible operations.

03

Decision record

Policy result, reviewer identity, approval or denial, and any threshold that triggered the route.

04

Execution result

Connector response, changed resource identifiers, error output, and timing.

05

Recovery path

Rollback command, compensation step, checkpoint, or incident note tied to the action.

Tamper-evident chain

Every production action event is linked to the prior event. Changing a request, decision, or execution result breaks verification.

Policy and approval evidence

The audit trail records why an action was allowed, blocked, or escalated, not just that a tool call happened.

Recovery evidence

Rollback and compensation data is captured with the original action so incident review starts from facts.

Production action review checklist

Use this as the baseline for whether an agent action was controlled well enough to trust in a real incident.

Can we see the exact intended effect?
Can we see affected systems before execution?
Can we see who approved or denied it?
Can we verify the record was not edited?
Can we recover or compensate from the captured plan?
Can security export evidence without asking engineering?