Ten questions that separate accountable AI from a black box. If you can't answer them with evidence, that's the gap to close.
For each question below, ask whether you can back the answer with independently verifiable evidence — not a dashboard, a screenshot, or a promise. Every 'no' or 'only our word' is a place where an audit, an incident, or an enterprise security review will find daylight.
Every consequential AI action produces a record you can retrieve later
That record is tamper-evident — edits are detectable
The record can be verified by someone outside your organization
You can prove when the action happened, independent of your clock
The decision rationale is captured with the action, not reconstructed
High-impact actions require human approval before executing
Autonomous actions are bounded by explicit policy (blast radius, windows)
You can prove a fix actually worked, not just that a command was sent
Agent tool calls (MCP/API) are governed and receipted, not unguarded
Records survive longer than your log-rotation and retention windows
'Trust our audit dashboard' as the answer to any of the above
Evidence that only exists inside the system being audited
Autonomy with no policy ceiling or human-approval path
By design, all ten are 'yes': every autonomous action is policy-gated (Arbiter), optionally human-approved (Citadel), simulated first (Digital Twin), verified for real outcome, and sealed into a tamper-evident, Bitcoin-anchored ProofLink receipt anyone can verify.
Score your systems against the ten questions, then close the gaps with provable operations.
No credit card · Free Pulse scan in 60 seconds · Cancel anytime