AIUC-1
Prepare evidence for selected AIUC-1 controls.
AIUC-1 includes requirements for restricting unsafe tool calls, assigning accountability for AI system changes, and logging AI system activity. The records below may support review when combined with implementation and operational evidence.
AIUC-1 D003: Restrict unsafe tool calls AIUC-1 E004: Assign accountabilityAIUC-1 E015: Log AI system activitySelected-control guide mapped against the July 15, 2026 release of AIUC-1 and reviewed October 7, 2026. AIUC-1 is revised quarterly and control sub-numbers have changed between releases, so each row cites the requirement by ID and the activity by name. Each row also notes whether the standard lists the activity under Should include or May include. This mapping does not assert AIUC-1 certification, an auditor's acceptance of any record, or satisfaction of the full standard.
What the evidence can contribute.
Permission Protocol’s suggested mappings below are for review. Confirm the fields available in your integration and whether the artifact is independently signed. Authorization evidence alone does not prove execution, complete coverage, or compliance.
D003: tool-call safeguards
Mandatory requirement, automation capability. Activities listed under Should include: tool authorization and validation, rate limits for tools, tool call log.
- Potential receipt or decision evidence
- Tool rules, decision logs, and approval evidence for calls inside the configured boundary.
- Your team must establish
- Implement and test authorization, validation, monitoring, and applicable limits. A decision record does not enforce rate or transaction limits, and it does not log every tool invocation.
D003: human approval
Mandatory requirement, automation capability. Activity listed under May include: human-approval workflows.
- Potential receipt or decision evidence
- A named human decision tied to the specific action reviewed, with the decision time, where the integration supplies that record.
- Your team must establish
- Define sensitive operations, enable an appropriate approval workflow, confirm the approver's authority, and test denials, timeouts, and bypass paths.
E004: approval of AI system changes
Mandatory requirement, universal. Activity listed under Should include: change approval policy and records.
- Potential receipt or decision evidence
- A named approval bound to the change it covers, such as a commit SHA, for AI system changes routed through a deploy gate.
- Your team must establish
- Define which AI system changes require approval, assign an accountable lead for each, and keep the supporting tests and rationale. Approval of a runtime action, such as a payment, is not evidence of approval of a system change, and signing an approval is not signing a build or model artifact.
E015: approval records in agent logs
Mandatory requirement, universal. Activity listed under May include: AI agent logging implementation.
- Potential receipt or decision evidence
- An approval record carrying the approver, decision time, and outcome, to join to the execution it authorized.
- Your team must establish
- Log the rest of the execution chain, including tool parameters and results, delegations, and provenance. Keep the join between each approval and its execution record.
E015: log integrity
Mandatory requirement, universal. Activity listed under May include: log integrity protection.
- Potential receipt or decision evidence
- A signed approval record that a reviewer can check against published keys, where the hosted service issues it.
- Your team must establish
- Protect the whole log against alteration, deletion, and reordering, and reconcile approvals against the execution source. A valid signature on one record does not show that no record is missing.
B006: pre-execution checks
Mandatory requirement, automation capability. Activity listed under May include: execution-level safeguards.
- Potential receipt or decision evidence
- Authorization evidence for a pre-execution policy check at the configured gate.
- Your team must establish
- Show that the enforcement point waits for that decision and obeys it, and test bypass paths. Sandboxing, tool-definition integrity checks, and configuration scanning are separate safeguards.
C007: human review of flagged outputs
Not a mandatory requirement. Activity listed under May include: human review workflows.
- Potential receipt or decision evidence
- Attributed review decisions with timing, for outputs routed to a configured gate.
- Your team must establish
- Define high-risk output criteria, implement detection, assign reviewers, and review the workflow's effectiveness over time. A decision record is neither the criteria nor the detector.
Build an evidence pack for one workflow.
Agree the requirement with your reviewer. Collect the configuration, approval records, verification results, exception handling, and tests for the chosen path. Evaluate gaps before expanding.