Capability

Evidence & Assurance Engineering

Build an evidence record your team can verify and explain.

Engineer verifiable records of important system actions, with defined capture, integrity checks, key custody and evidence export that your team can operate and explain.

A log entry is useful only when you know what produced it, what it covers, and how to check it. Wilkes & Liberty engineers the evidence path around consequential system actions so operators and reviewers can examine a record and understand its limits.

When this work is needed

This practice is for teams that must demonstrate how a system behaved: an AI agent changed content, an administrator granted access, a protected file was released, or a payment was reconciled. The work begins with the question the reviewer needs to answer.

  • Important actions are scattered across application logs and vendor dashboards.
  • Administrators can alter the same records they are expected to account for.
  • A policy requires evidence, but nobody has tested capture or the response when logging fails.
  • An assessor needs a bounded evidence set without receiving unnecessary personal or operational data.

What we build

We identify the events, actors and systems that matter, define the evidence contract, and connect the producers to a record that can be checked. Verification and operational response are part of the implementation.

  • An event and coverage map naming each producer, its actor identity, the action recorded and known gaps.
  • Tamper-evident records with a signing and key-custody model appropriate to the agreed threat model.
  • Scheduled integrity checks and actionable failure reporting.
  • An explicit choice for each producer: refuse the action when required evidence cannot be written, or continue with a documented gap and response.
  • Independent anchoring where required, with the trust boundary and operational ownership documented.
  • Data-minimized export, custody procedures, retention requirements and tested key-rotation and recovery paths.

How an engagement works

First, the client identifies the decisions or controls that need evidence and the people who will review it. We agree the covered events, capture requirements, retention obligations, threat model and acceptance checks. Then we instrument a bounded workflow and test the evidence from production through verification and export.

The control owner decides what must be evidenced and how exceptions are handled. Our engineers implement capture and integrity controls. The designated reviewer checks the resulting record against the original question. A named operator takes responsibility for routine verification and failure response.

The practice behind Assay

Assay is the evidence and assurance platform. Evidence & Assurance Engineering is the work of integrating that platform into a real operational process and establishing what its evidence can support.

Audit Chain is Assay’s published Drupal component. Sentinel controls governed agent access; Assay supports checking the integrity of the resulting record. Identity, event capture and independent anchoring each have their own responsibilities. Installing the component does not settle those responsibilities automatically.

What you keep

  • An evidence coverage map, event definitions and documented gaps.
  • The agreed integrations, verification configuration and operational alerts.
  • A key-custody and rotation procedure with responsibilities assigned.
  • Export and retention procedures that state what the recipient can independently verify.
  • Acceptance evidence and runbooks another operator has walked.

How we establish completion

We test the claimed boundary directly. A passing verification check is useful only when the agreed failure cases produce the expected failure and response.

  • An agreed event is captured with the expected actor and context.
  • A controlled alteration is detected, and the verdict identifies the relevant integrity failure.
  • Loss of signing or export capability produces the documented behavior for each producer.
  • Key rotation preserves verification of the retained history.
  • The receiving reviewer can explain which checks the export supports and which require the source system.

Scope and adjacent work

Tamper evidence helps establish record integrity. It does not establish that every real-world event was captured or that a producer reported the truth. Capture completeness, identity quality, storage protection and independent checkpoints must be addressed explicitly.

Compliance & Security Governance owns the policies, control responsibilities and compliance documentation around the system. Evidence & Assurance Engineering implements the evidence path those controls rely on. The work does not confer certification, replace an independent assessment, or replace a backup, operational monitoring or records-management program.

Key capabilities

  • Evidence coverage

    Map the events, actors, producers and gaps before selecting what to record.

  • Integrity and custody

    Implement tamper evidence with explicit signing, key custody and trust boundaries.

  • Verification and response

    Exercise failure cases and connect integrity verdicts to an operational response.

  • Bounded evidence export

    Deliver the information a reviewer needs, with minimization and verification limits stated.

Related solutions