SOC 2 evidence

What SOC 2 evidence should teams keep for AI coding agents?

For SOC 2 and customer reviews, link each AI-assisted change to existing change-management, access-control, deployment, monitoring, and incident records.

Last updated: August 13, 2026

Use the same evidence expected for other software changes, then preserve the agent or tool context. Connect the requester, PR, workflow, credential, reviewer, deployment target, and outcome to the controls your auditor is testing. The applicable evidence depends on your system and the scope of the review.

Evidence to retain

Change control

Repo, branch, PR, requester, reviewer, workflow file, job, validation, and merge or release decision.

Access control

Agent or workflow identity, credential source, token scope, service account, inherited permission, and owner.

Approval

Who approved a credentialed action or production change, what policy applied, and why it was allowed.

Outcome

Job result, deployment result, target system, validation evidence, retained logs, and remaining gap.

Map evidence to common audit asks

Audit or customer ask AI-assisted delivery evidence
Was the change reviewed and approved? PR review, workflow owner, approval reason, policy decision, timestamp.
Was privileged access controlled? Credential source, token scope, service account owner, environment protection, revocation path.
Was deployment or release controlled? CI job, deploy target, required reviewer, validation output, release result.
Can the team investigate later? Retained logs, actor/session context, target system, outcome, and incident traceability.

What the audit record needs

Link the approved tool and model to the workflow that could write, deploy, use credentials, publish, or affect production. Keep the review and outcome records with that path.

Evidence packet shape

human owner -> agent workflow -> repo/PR -> CI/CD -> credential -> action -> target -> approval -> outcome evidence

This packet helps engineering and security answer customer questionnaires, audit requests, and incident reviews without reconstructing the path from chat history, PR comments, CI logs, and credential systems after the fact.

Primary source

Prepare evidence before the questionnaire arrives.

Clyra maps selected AI-assisted delivery paths and returns a redacted evidence packet your engineering and security reviewers can use.

Map one workflow