Product · owlaudit

OwlAudit

OwlAudit provides Hash Chain audit ledgers and policy-driven HITL / HOTL / HOOL three-tier interventions. Human review tickets support pending states, escalations, timeout fallbacks, and decision provenance. Synchronous evaluation runs on connected NodalOS hooks; generic ingest logs records without blocking past executions.

OwlAudit hero
OwlAudit logo

OwlAudit

Compliance Audit & HITLAI Agent compliance audit and human-in-the-loop (HITL) governance

Committed actions are verifiable and traceable; on connected NodalOS hooks, policy-triggered high-risk actions await human sign-off.

Verifiable
Recompute hashes and detect gaps on committed chains
Real-Time Blocking
Synchronously rejects actions matching HITL policies on NodalOS hooks
Three Tiers
HITL · HOTL · HOOL

Typical pains

Agents call production APIs directly without human oversight or guardrails

Post-incident forensics lack complete, tamper-evident audit trails

Compliance policies fail to translate into concrete Agent behaviors

Capabilities

Hash Chain AuditCommitted records are verifiable, gap-checkable, and support checkpoints. Does not verify external data veracity or perform offsite WORM anchoring
Multi-Chain ArchitectureMain chain is mandatory; HITL, financial, and compliance events split by topic, with optional program and group sub-chains
Three-Tier InterventionHITL, HOTL, and HOOL are selected via policy action_type, not independent toggles. Unmatched events default to HOOL pass-through
Human Review TicketsPending states, escalation chains, timeout fallbacks, and decision provenance; optional webhooks. Role routing and PathPilot writebacks apply only to connected paths
Policy EngineExecutes actions on policy matches. NodalOS Evaluate defaults to pass on non-matches; ingest mode logs records without blocking
Policy Version ProvenancePolicy changes bump dual version numbers in the same transaction as the audit record; NodalOS Evaluate includes those IDs on a match. Version IDs trace the then-current policy, they are not a full policy-text snapshot
Node Delivery IntegrityReports gaps in landed records by NodalOS instance sequence. Does not distinguish a silent node from normal idle, and does not cover source-side drops that never received a sequence number
Budget Policy ReplicasStores and serves per-layer replicas (customer default / Program / Task) without pre-merging; consumers such as PathPilot apply the overlay
Compliance FreezeWrites freeze records. On NodalOS hooks, opens a review ticket and blocks the action; ingest mode opens review only when policies specify a category. Pausing PathPilot tasks requires connected writebacks
Compliance ReportsCompliance status summaries and templated reports. Does not produce cryptographically signed compliance packages or replace regulatory filings
NodalOS Synchronous EvaluatorFunctions as a synchronous external evaluator on connected hooks. Unhooked calls and internal NodalOS hard limits bypass this evaluator
Standalone DeploymentBuilt-in audit chain, HITL engine, policy management, and reporting; integrations with PathPilot, HeronSentry, AULO, and NodalOS remain optional
HITL Approval Veto RateContributes human review veto frequency to performance tracking, rather than subjective quality or compliance scores

Does / does not

Does
  • Hash Chain audit (verifiable, gap detection)
  • HITL / HOTL / HOOL three-tier intervention (policy-driven)
  • Dual-version provenance on policy changes
  • Human review tickets, escalations, and timeout fallbacks
  • Compliance freeze records and compliance reports
  • Contributions to HITL review veto rate (rejection frequency tracking)
Does not
  • Does not replace corporate legal and compliance consulting
  • Does not score Agent quality or assign synthetic compliance ratings
  • Does not replace existing enterprise compliance record systems
  • Does not provide GRC / SIEM export tooling
  • Does not guarantee the upstream factual truth of reported events

Integrations

NodalOS synchronous evaluation on connected hooks (optional)AULO consumes HITL review tickets / Outbox (optional)PathPilot escalation event ingestion and limited writeback (optional)Ingests audit-related telemetry exports from HeronSentry (optional)

Related products

Next steps

SYSTEM READYproduct/owlaudit