Runtime event
Model call, tool call, drift signal or control decision.
Decision and outcome
Allowed, constrained, held or denied.
Verification metadata
Timestamp, policy hash and version, input and output hashes, runtime signals, the control that ran and its outcome, and the record ID. The record is Ed25519-signed by the operator and hash-chained. Records minted through the portal may also carry a Glacis service-operated witness countersignature and inclusion proof; SDK or self-hosted records may be operator-signed only.
Sensitive payload
A record can leave out prompts, outputs, PHI, customer data, code, credentials and proprietary context, keeping only the fields and hashes a verifier needs.