An agent's receipt starts from the six items the federal catalog of security controls asks every audit record to establish: what type of event occurred, when, where, its source, its outcome and who or what was involved (Special Publication 800-53, Revision 5). An agent needs five more fields on top: the setup it ran on, the evidence it read, the approval, its stated reason and the cost. The system that carries out the action writes the receipt at that moment, into a store the agent cannot change. A person reads a weekly summary of them inside a time budget set in advance.
The six items of a standard audit record
The National Institute of Standards and Technology publishes the catalog for federal systems. Its control on the content of audit records maps onto an agent's work line by line.
| The standard asks for | On an agent receipt | Example (made up) |
|---|---|---|
| Type of event | The action, in plain words | Sent a reply to a scheduling request |
| When | Date and time, with time zone | September 3, 10:14 a.m. Central |
| Where | The system and the place it acted | The shared inbox, the thread about the Hill Street job |
| Source | What started it: a message, a schedule or a person | A new message from the customer |
| Outcome | Done, failed, stopped or undone | Sent |
| Identity | The agent, the person who approved, the people it reached | The scheduling agent; approved by the owner; one customer |
Five more fields for an agent
- The setup it ran on. The version of its instructions, the model and the tools it held. When behavior changes, this field shows what changed.
- The evidence. Links to the records the agent read before it acted. A link lets the reader check the source and avoids a second copy of private data.
- The approval. Who approved, when, and whether they edited first. Edits and rejections are the record that decides a task's level (how levels are earned).
- Its stated reason. Written into the receipt at the moment it acts, before anyone asks.
- The cost. Tokens in and out, and the price per token in force that day.
A record with no evidence behind it
In a March 2023 filing in federal court in Manhattan, two lawyers at a New York firm cited judicial decisions that ChatGPT had produced and that did not exist. One of the lawyers, by his own account, asked ChatGPT whether one of the cases was real, and it answered that the case existed and could be found in the standard legal databases. On June 22, 2023, Judge P. Kevin Castel sanctioned the two lawyers and their firm $5,000 and wrote that existing rules give attorneys a gatekeeping role over the accuracy of their filings (opinion and order on sanctions, Mata v. Avianca).
A receipt that links each source the agent read gives the reader something to click, and a citation with no link behind it stands out. Asking the agent afterward only gets its own account, which is what the lawyer got from ChatGPT.
Out of the agent's reach
Protection comes next in the same control set: audit information is to be kept from unauthorized access, modification and deletion. In this guide's design, the agent writes receipts through a path that can add entries and never change them, and only a person can export or delete them.
How long to keep receipts is left to each organization's records policy, and the catalog names the purpose: support for after-the-fact investigations of incidents, and regulatory and organizational retention requirements. Industry rules may set a minimum, and this guide is general information, not legal advice.
Audit records can also expose people, the catalog notes: what they hold can reveal information about individuals and raise privacy risk. A receipt that stores a link to the customer's message, with no copy of the message, keeps that risk small.
The weekly read inside a fixed budget
Review happens at a frequency each organization sets, and the catalog asks it to look for signs of inappropriate or unusual activity. Invented for illustration: a small company reads one weekly summary in a fifteen-minute block, and for each task the summary shows:
- how many actions it took, and at what level
- approvals with edits, and rejections with their reasons
- any stop, failure or undo
- any action of a kind the task has never taken before
- cost for the week, and cost per completed action
When a week no longer fits in the block, promotions and new tasks pause until it does.
Cost per completed action
Cost per completed action is a task's model and tool cost for the week divided by the actions that finished and were not rejected. The task and every number in this table are made up: one week of a scheduling task.
| Line | Example (made up) |
|---|---|
| Drafts produced | 120 |
| Approved with no change | 84 |
| Approved after an edit | 27 |
| Rejected | 9 |
| Model and tool cost for the week | $6.00 |
| Cost per completed action | $6.00 divided by 111, about 5.4 cents |
| A person's time in the approval queue | 24 minutes, about 13 seconds per completed action |
The 24 queue minutes and the fifteen-minute read add up to 39 minutes, inside a 45-minute weekly budget.
Where a receipt trail falls short
- Receipts written after the fact. A summary the agent writes at the end of the day comes from the agent, and nothing in it can be checked against the systems it touched.
- Logging everything. Whole messages and documents copied into logs build a second store of private data that then needs protecting. Fields and links carry the same record.
- A read with no owner. On August 1, 2012, a Knight Capital system sent 97 automated emails flagging the fault behind that morning's trading losses before the market opened; the staff who received them generally did not review such messages, and nobody acted on them (Securities and Exchange Commission order, October 16, 2013).
- A store that cannot answer questions. The database behind these receipts is data engineering, outside this site.
The worksheet
The agent readiness worksheet has the receipt checklist and the weekly time and cost arithmetic, with blank rows for a reader's own numbers.
Sources
All sources were read on September 27, 2026.
- National Institute of Standards and Technology, Special Publication 800-53, Revision 5: Security and Privacy Controls for Information Systems and Organizations, September 2020, with updates to December 10, 2020, the controls on content of audit records, audit record review, protection of audit information and audit record retention.
- United States District Court for the Southern District of New York, Mata v. Avianca, opinion and order on sanctions, case 22-cv-1461, June 22, 2023, court filing copy held by CourtListener.
- United States Securities and Exchange Commission, In the Matter of Knight Capital Americas LLC, Release No. 34-70694, October 16, 2013.