Was this agent run tampered with?
Open an evidence bundle to check its hash chain and signatures, then read what the agent actually did.
No bundle at hand?
- 1Open a bundleA bundle is the .zip an agent operator exports as evidence of a run.
- 2Confirm the signerEnter the signer's principal id, which you got from them and not from the file.
- 3Read the runSee every step, what left the host, and what policy blocked.