Security tooling often treats the audit trail as exhaust—the thing retained in case something goes wrong. A governance control plane has to start from the opposite premise.

Evidence is part of the result

When an agent acts on a person’s behalf, governance produces more than an allow or deny. It produces a durable account of the actor, selected identity, exact tool, effective policy, and outcome. The dashboard and consent screen exist to make that record true and understandable.

If evidence can be reconstructed only after the fact, the most important details are vulnerable to gaps. Govna therefore commits an audit intent before a connector call is dispatched. If that commit fails, the call is denied.

A call that cannot be receipted is a call that does not happen.

The fail-closed rule

A receipt people can inspect

The useful unit is not an opaque log line. It is a structured event that an engineer, administrator, or auditor can sample without guessing what each field means. The example below is illustrative; production identifiers and hashes come from the runtime ledger.

GOVNA · AUDIT RECEIPTexample_evt_9F3A21C4
time
2026-07-15 09:41:07 UTC
actor
agent client · organization member
identity
atlassian · selected identity
tool
jira.create_issue
policy
profile:debugging
allowedsealed · sha256:illustrative

Show the control, label the claim

Evidence does not turn an unverified system into a certified one. Govna’s Security Center separates implemented controls, repository-backed proof, operational exercises, and independent attestations. Where verification has not happened, the site says so.

That distinction is deliberate: spend first on controls that stop incidents, then pursue independent attestation when customers and economics justify it. Until then, show the work and state exactly what has—and has not—been independently verified.

Inspect the current proof ledger.

See implemented controls, limits, and evidence without a sales call.

Open the Security Center