Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It covers Configuration → Agent Ledger. It sits beside Permissions and roles and the AI governance security page. For what the module is, see Agent Ledger and AI governance.
Your Coverbase representative turns on the third-party lifecycle features, including the Agent Ledger, for your organization.
The Agent Ledger records every action an AI agent takes on your organization’s data, and holds the settings that decide what agents may do on their own. The mistake people make most often is turning on learning before anyone has looked at the examples. Learning uses every enabled example. Read Learned examples first and switch off any correction you would not want repeated. Open Configuration and choose Agent Ledger. Changing settings needs a role that can change organization settings.

Step 1: Read the ledger

Actions lists what agents did, newest first, with Time, Agent, Action, Confidence, what it Read, and the Human Decision. Search, filter by agent, action, decision, outcome, record type, date or confidence, or show only actions Awaiting decision. The header counts today’s actions.
Agent Ledger page listing actions by the evidence, monitoring, radar and intake agents with confidence scores and decisions such as Accepted, Applied under org policy and Awaiting review, beside the agent policy switches and the Privacy panel

Configuration, then Agent Ledger: agent actions with their confidence and human decision, beside What Agents May Do and Privacy.

Open a row to see the Record it acted on, what it Read, what it Cited, its Confidence, the Models it called and how many, and how many personal details were redacted.

Step 2: Record a decision

On an action awaiting review, choose Accept, Edited and accepted or Reject, and confirm. A Note is saved with your decision in the ledger and its audit export. Rejecting needs one. The row then reads, for example, Accepted by and the person’s name. To decide several at once, select them and choose Accept or Reject. Only completed actions nobody has decided are changed. The result says how many were left as they were. An action taken under one of your policies reads Applied under org policy, one a policy held back reads Held back by org policy, and a failed action reads Failed.

Step 3: Choose what agents may do

Under What Agents May Do, switch on only the actions you are content for an agent to take without a person. Only admins can change them. Each switch is enforced where the agent acts: Auto-close low tier reassessments with no changes and Send anything to a vendor without review read No agent does this yet, so it stays off. Accept risk or close an issue reads Always needs a person; this cannot be delegated.

Step 4: Decide on redaction

Under Privacy, Redact personal data before model calls is off by default. Turned on, email addresses, phone numbers, account and tax numbers (IBANs and US tax IDs), and the full names of your users and your vendors’ contacts become placeholders before a request reaches the model, and the answer is restored before anyone sees it. Keep in mind:
  • Redaction does not reach inside images or attached documents, such as a PDF the model reads directly.
  • If Coverbase cannot confirm the setting for your organization, the model call fails rather than going out unredacted.
The privacy panel also states where your models run, that customer data is not used for training, and that bank and tax identifiers are sealed per field.

Step 5: Manage learning

When a reviewer overturns a control evaluation, clearing or flagging an issue, a daily job turns the correction into a learned example for that control. Learned examples lists each with the Control, the Reviewer Decision (Cleared an issue or Flagged an issue), the Reviewer Note and Use.
1

Review the examples

Switch off Use this example on any correction that should not be repeated. Refresh from overrides collects new corrections now instead of waiting a day.
2

Write guidance

Under Evaluation Guidance, describe how your organization reads its controls, for example which evidence you accept for a vendor’s attestation. It applies to every control evaluation. A control’s own guidance wins where the two differ. Click Save guidance.
3

Turn it on

Turn on Use in evaluations. From then on, a control’s evaluation uses up to five of its enabled examples and your guidance. With it off, evaluations run unchanged.

Step 6: Export for an audit

Filter the ledger to what the audit needs (agent, action, decision, outcome, record type, date or confidence), then click Export filtered for audit (Export for audit with no filter set). The CSV is prepared in the background, up to 50,000 actions, and downloads when it is ready. You are also notified. Each row carries the citations, models, redaction count and human decision. A value a spreadsheet would run as a formula is written as text.

Troubleshooting

AI governance

How models are selected, tested and constrained.

Agent Ledger and AI governance

What the module does.

The analyst and reviewer guide

Correcting an evaluation, which feeds learning.

Monitoring plans

Signal re-timing, one of the agent policies.