An audit trail is only as good as the question it can answer. For regulated finance, the question is rarely "did a payment happen?" It is "was this operation authorised, by whom, under what rules?" When the actor is an agent, answering that requires more than a transaction log. It requires a record that can reconstruct an operation all the way back to the exact version of the policy it executed.
What has to be recorded
A reconstruction needs three anchors, held together for every operation:
- the principal — the person or company legally behind it;
- the agent — the specific registered identity that acted;
- the policy version — the mandate in force at that moment.
Without all three, a record describes what happened but not whether it was permitted.
Why the policy version is the hard part
Rules change. Limits are adjusted, counterparties added, thresholds revised. A log that records an amount without pinning it to a policy version cannot tell an auditor which rules applied when the operation was made. This is why a policy hash matters: it binds each operation to one identifiable set of rules, so a later review can confirm that a payment was inside the mandate that existed at the time — not the mandate that exists now.
Reconstructing an operation
With these anchors, reconstruction becomes mechanical. An auditor can trace an operation to its principal, confirm the agent's identity, and check the amount against the policy version recorded. Where an operation exceeded a threshold, the record shows the escalation to a human and the decision taken. The trail answers the question directly, without guesswork.
In short
- A useful trail answers whether an operation was authorised, not just that it happened.
- Every operation ties to a principal, an agent and a policy version.
- A policy hash pins each operation to the rules in force at the time.
- Reconstructing becomes mechanical, not archaeological.
This is general information, not legal or compliance advice.
See the accountability model behind the protocol.