Skip to content
WATCHBILL from Blue Jacket
For reviewers · Public v1.5 · Updated 2026-09-28

Seven records. Hand them over.

When a reviewer, auditor or buyer's governance team comes looking, the question is not how a model reasoned. It is who authorized the work, what the agent was and was not allowed to do, what was checked, what was blocked, and whether the record has changed since.

Download the packetZIPPDF

v1.5 · real watch 17 Sep 2026 · cover built 28 Sep 2026 · hashes on last page of the PDFZIP sha256 029422937077dbf1752009a624a28566ce91196d7739efff68b09f92db770b3ePDF sha256 fd08ca8ec612f56682f8487b57feaa24f0b9585ad311e568b3f7fd15ffa32b50

Filter by framework

A real watch, redacted · 17 September 2026

Record 03 · Refused-action record

Executor seat WBX27, paired with orchestrator seat WBO27.

  1. 07:36:02 ET

    A scripted delete-and-rebuild of a scratch copy of test files.

    Refused before it ran.

    A command reserved to the owner.

  2. 08:25:34 ET

    A read-only command, over-blocked.

    Refused before it ran.

    Over-block: refused as a reserved operation, though it was read-only.

  3. 11:23:46 ET

    A read-only command, over-blocked.

    Refused before it ran.

    Over-block: refused as a reserved operation, though it was read-only.

  4. 11:25:12 ET

    A read-only command, over-blocked.

    Refused before it ran.

    Over-block: refused as a reserved operation, though it was read-only.

Three of the four were over-blocks of read-only commands; the record keeps them as refused.

[redacted: paths, commands, file names, reason codes]

Scope

  1. One slice, not the whole framework.
  2. Evidence, not a compliance conclusion.
  3. Partials are named.
  4. Access enforcement is partial. The refusals on this page come from a check made before an agent acts. It is not a sandbox, and it does not inspect every path an agent could take. Every access-control mapping that rests on it is marked partial.
  5. Self-produced, not yet attested. No SOC 2 examination. No SOC 2 criterion on this page has been examined by a service auditor.
Read the full scope note

Watchbill™ governs the work AI agents do: Supervised Autonomy, with every act authorized, bounded, checked and recorded in an append-only record. When a reviewer, auditor or buyer's governance team comes looking, the question is not how a model reasoned. It is who authorized the work, what the agent was and was not allowed to do, what was checked, what was blocked, and whether the record has changed since.

This page lists the evidence Watchbill produces to answer those questions, and the framework identifiers each piece of evidence supports. It describes outputs, not how they are produced. Samples and the full per-item mapping are available under engagement.

  • One slice, not the whole framework. Watchbill™ produces evidence for the agent-authority slice of these frameworks: who authorized an AI agent, what it could and could not do, what was blocked, what a human committed, and whether the record has changed since. Most requirements in SOC 2, NIST SP 800-53 and the NIST AI RMF sit in the rest of your control environment (governance, people, vendors, access to your other systems, encryption, availability, incident response, risk assessment), and that remains yours. The short lists below are the requirements this evidence actually supports, not a coverage score.
  • Evidence, not a compliance conclusion. Each item below supports the cited framework requirements. None of it is a conclusion about compliance with any framework, standard or law; that conclusion belongs to your auditor and your counsel.
  • Partials are named. Where evidence covers only part of a requirement, the mapping says partial. It is never stretched to fill a cell.
  • Access enforcement is partial. The refusals on this page come from a check made before an agent acts. It is not a sandbox, and it does not inspect every path an agent could take. Every access-control mapping that rests on it is marked partial.
  • Self-produced, not yet attested. The evidence is produced by Watchbill's own controls and has been exercised by its owner. No third party has attested to it yet.
  • No SOC 2 examination. No SOC 2 criterion on this page has been examined by a service auditor.
  • Process, not interpretability. Watchbill says nothing about why a model produced a given output.
  • The seat check has a limit. The gate does not see every form a command can take, and the seat check does not identify the caller.
  • Open items from the sample watch. Open items from this watch were recorded and routed to our own core work; they are left out of the packet.

The evidence, and where it maps

CC6.1 supports the requirementCC7.2partial covers part of itNot mapped no claim made

Supports means the evidence addresses what the requirement asks of the agent-authority slice; partial means it addresses some of that, and the rest sits elsewhere in your controls.

  1. 01

    Authorization record

    Who put this agent on watch, and until when?

    Which agent role was authorized to act, by whom, and when that authority began and ended

    • GOVERN 3.2
    • LLM06partial
    • ASI03
    • CC6.1
    • AC-2
    • MANAGE 2.4partial
    • CC6.2
    • Art. 14(4)(e)partial
    • +2
    View record
  2. 02

    Human approval record

    Who committed the irreversible act?

    Every irreversible action was taken by a named human, not by the agent

    • GOVERN 3.2
    • LLM06
    • ASI02
    • CC6.3
    • AC-5
    • MAP 3.5
    • ASI03
    • CC8.1
    • CM-5
    • Art. 14(4)(d)partial
    • +4
    View record
  3. 03

    Refused-action record

    What did the agent try that was blocked, and why?

    What an agent attempted and was blocked from doing, with the reason

    • MEASURE 2.8
    • ASI10partial
    • CC7.2partial
    • AU-2
    • AML.T0053
    • MEASURE 2.4partial
    • AU-3
    • AML.T0101
    • MEASURE 2.7partial
    • AU-12
    • AC-3partial
    • AC-6(10)partial
    • Art. 12partial
    • +7
    View record
  4. 04

    Tamper-evident filing record

    Has this file changed since it was filed?

    The record of work has not been altered since it was filed, with a verification result that shows it

    • MEASURE 2.8
    • CC7.2partial
    • AU-9partial
    • Art. 12partial
    View record
  5. 05

    Scoped work order

    What was this session allowed to do, and where does it stop?

    Each task was authorized in advance, bound to the session that performs it, with defined stop points

    • MAP 3.5partial
    • LLM01partial
    • ASI01partial
    • CC8.1
    • CM-3
    • Art. 14(4)(e)partial
    View record
  6. 06

    Independent re-verification receipt

    Was the agent's claim checked against live state?

    Each claim an agent made was checked against the system's actual state before it was accepted

    • MEASURE 2.8
    • LLM09
    • ASI09
    • CC4.1
    • CA-2
    • MEASURE 1.3partial
    • CA-7
    • +2
    View record
  7. 07

    Provenance-labelled report

    Which lines were measured, which were human-reported, which were dated?

    What this record would show: where each figure came from, whether measured, reported by a person, or carried from a dated source.

    • MEASURE 2.8
    • LLM09partial
    • ASI09partial
    View record

The records

01

Authorization record

Who put this agent on watch, and until when?

Which agent role was authorized to act, by whom, and when that authority began and ended

A real watch, redacted · 17 September 2026

Record 01 · Authorization record

Seat opened on 17 September 2026 by the owner.

Authority: read and propose. Nothing was installed outside a test copy, and nothing left the machine.

[redacted: registry name, working-surface names]

FrameworkIdentifierFit
NIST AI RMFGOVERN 3.2supports
NIST AI RMFMANAGE 2.4partial
OWASP LLMLLM06partial
OWASP AgenticASI03supports
SOC 2CC6.1supports
SOC 2CC6.2supports
NIST SP 800-53AC-2supports
EU AI ActArt. 14(4)(e) Human oversight: intervene or interruptpartial: disengages authorized action; a planned halt

Back to the records

02

Human approval record

Who committed the irreversible act?

Every irreversible action was taken by a named human, not by the agent

A real watch, redacted · 17 September 2026

Record 02 · Human approval record

Every irreversible act in this watch was the owner's: three filings, the placement of the order, one disposal, two scripted runs, and the executor relaunches.

Three rulings were filed by the owner's hand: WB 138, WB 139 and WB 140.

[redacted: script names, paths]

FrameworkIdentifierFit
NIST AI RMFGOVERN 3.2supports
NIST AI RMFMAP 3.5supports
OWASP LLMLLM06supports
OWASP AgenticASI02supports
OWASP AgenticASI03supports
SOC 2CC6.3supports
SOC 2CC8.1supports
NIST SP 800-53AC-5supports
NIST SP 800-53CM-5supports
EU AI ActArt. 14(4)(d) Human oversight: override or reversepartial: every irreversible act is the human's

Back to the records

03

Refused-action record

What did the agent try that was blocked, and why?

What an agent attempted and was blocked from doing, with the reason

A real watch, redacted · 17 September 2026

Record 03 · Refused-action record

Executor seat WBX27, paired with orchestrator seat WBO27.

  1. 07:36:02 ET

    A scripted delete-and-rebuild of a scratch copy of test files.

    Refused before it ran.

    A command reserved to the owner.

  2. 08:25:34 ET

    A read-only command, over-blocked.

    Refused before it ran.

    Over-block: refused as a reserved operation, though it was read-only.

  3. 11:23:46 ET

    A read-only command, over-blocked.

    Refused before it ran.

    Over-block: refused as a reserved operation, though it was read-only.

  4. 11:25:12 ET

    A read-only command, over-blocked.

    Refused before it ran.

    Over-block: refused as a reserved operation, though it was read-only.

Three of the four were over-blocks of read-only commands; the record keeps them as refused.

[redacted: paths, commands, file names, reason codes]

FrameworkIdentifierFit
NIST AI RMFMEASURE 2.8supports
NIST AI RMFMEASURE 2.4partial
NIST AI RMFMEASURE 2.7partial
OWASP LLMNot mappedno claim made
OWASP AgenticASI10partial
SOC 2CC7.2partial
NIST SP 800-53AU-2supports
NIST SP 800-53AU-3supports
NIST SP 800-53AU-12supports
NIST SP 800-53AC-3partial
NIST SP 800-53AC-6(10)partial
MITRE ATLASAML.T0053supports
MITRE ATLASAML.T0101supports
EU AI ActArt. 12 Record-keepingpartial: records refusals and filings, not every event

Back to the records

04

Tamper-evident filing record

Has this file changed since it was filed?

The record of work has not been altered since it was filed, with a verification result that shows it

A real watch, redacted · 17 September 2026

Record 04 · Tamper-evident filing record

Each row carries a link computed from the row before it. [redacted: link values]

Chain check on 27 September 2026 at 20:38 ET: passed, 864 chained rows after the starting checkpoint.

FrameworkIdentifierFit
NIST AI RMFMEASURE 2.8supports
OWASP LLMNot mappedno claim made
OWASP AgenticNot mappedno claim made
SOC 2CC7.2partial
NIST SP 800-53AU-9partial
EU AI ActArt. 12 Record-keepingpartial: records refusals and filings, not every event

Back to the records

05

Scoped work order

What was this session allowed to do, and where does it stop?

Each task was authorized in advance, bound to the session that performs it, with defined stop points

A real watch, redacted · 17 September 2026

Record 05 · Scoped work order

Order WB 143, "Watchbill packaging and distribution", cut on 17 September 2026 by orchestrator seat WBO27.

Scope: propose, never install. Writes to one staging area only.

[redacted: paths, file names]

FrameworkIdentifierFit
NIST AI RMFMAP 3.5partial
OWASP LLMLLM01partial
OWASP AgenticASI01partial
SOC 2CC8.1supports
NIST SP 800-53CM-3supports
EU AI ActArt. 14(4)(e) Human oversight: intervene or interruptpartial: disengages authorized action; a planned halt

Back to the records

06

Independent re-verification receipt

Was the agent's claim checked against live state?

Each claim an agent made was checked against the system's actual state before it was accepted

A real watch, redacted · 17 September 2026

Record 06 · Independent re-verification receipt

Every leg was checked by the orchestrator seat by re-measurement on disk, not taken from the executor's report.

One leg was refused on two blocking defects, reworked, and then accepted.

[redacted: digests, instruments]

FrameworkIdentifierFit
NIST AI RMFMEASURE 2.8supports
NIST AI RMFMEASURE 1.3partial
OWASP LLMLLM09supports
OWASP AgenticASI09supports
SOC 2CC4.1supports
NIST SP 800-53CA-2supports
NIST SP 800-53CA-7supports

Back to the records

07

Provenance-labelled report

Which lines were measured, which were human-reported, which were dated?

What this record would show: where each figure came from, whether measured, reported by a person, or carried from a dated source.

NOT IN THIS WATCH

Not present in this watch. The slot is listed so the gap is visible. Nothing is substituted.

FrameworkIdentifierFit
NIST AI RMFMEASURE 2.8supports
OWASP LLMLLM09partial
OWASP AgenticASI09partial
SOC 2Not mappedno claim made
NIST SP 800-53Not mappedno claim made

Back to the records

How it runs

Watchbill is an MCP server.

It is launched by the operator's client from a standard MCP configuration.

No tool runs without a seat check.

A refused call is refused in the request path.

The limits below cover both layers: the operator seats that do our own work, and the server's seat check.

  • Gated, not caged.
  • The gate does not see every form a command can take, and the seat check does not identify the caller.
  • The operating-system fence covers one appliance configuration only.

Shape and delivery

Delivered as a private package with a detached manifest; placing it into a deployment is a named human's act, never an agent's.

Delivery is under engagement paperwork, by choice, so that contract review comes before any package leaves.

MITRE ATLAS note and EU AI Act table

On MITRE ATLAS. ATLAS catalogues adversary techniques, and most of this evidence documents governance rather than a counter to a named technique. The refused-action record is the exception: it evidences blocked attempts in the class of AI Agent Tool Invocation (AML.T0053) and Data Destruction via AI Agent Tool Invocation (AML.T0101).

EU AI Act (optional; applicability first)

Articles 12 and 14 bind high-risk AI systems as classified under Article 6 and Annexes I and III of Regulation (EU) 2024/1689. Watchbill is not asserted to be a high-risk system; a deployment falls in scope only through the classification of the system Watchbill governs. This is not a legal assessment.

Article Evidence that supports it Fit
Art. 12 Record-keeping Refused-action record; tamper-evident filing record partial: records refusals and filings, not every event
Art. 14(4)(d) Human oversight: override or reverse Human approval record partial: every irreversible act is the human's
Art. 14(4)(e) Human oversight: intervene or interrupt Authorization record (authority ended); scoped work order (stop points) partial: disengages authorized action; a planned halt

What is not claimed

  • No compliance conclusion, certification or attestation of any kind.
  • No third-party review of this evidence yet.
  • Nothing about model behaviour or interpretability.
  • ISO/IEC 42001 is not mapped on this page.

Sources (retrieved / verified 2026-09-25)

  • NIST AI RMF 1.0 (AI 100-1): https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
  • NIST AI 600-1, Generative AI Profile: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
  • OWASP Top 10 for LLM Applications 2025: https://genai.owasp.org/llm-top-10/
  • OWASP Top 10 for Agentic Applications: https://genai.owasp.org/
  • MITRE ATLAS: https://atlas.mitre.org/
  • AICPA Trust Services Criteria (2017, rev. 2022): https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
  • NIST SP 800-53 Rev. 5: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
  • EU AI Act, Regulation (EU) 2024/1689: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689

Framework versions referenced (verified 2026-09-25)

Framework Version referenced Primary source
NIST AI RMF AI RMF 1.0 (AI 100-1) + Generative AI Profile (AI 600-1) nvlpubs.nist.gov
OWASP for LLM Apps Top 10 for LLM Applications, 2025 genai.owasp.org
OWASP for Agentic Apps Top 10 for Agentic Applications, 2025 genai.owasp.org
MITRE ATLAS ATLAS matrix (atlas-data 5.6.0) atlas.mitre.org
SOC 2 AICPA Trust Services Criteria 2017 (rev. 2022) AICPA TSP §100
NIST SP 800-53 Rev. 5 (control catalog, as anchor) csrc.nist.gov
EU AI Act Regulation (EU) 2024/1689, Articles 12 and 14 (optional column) eur-lex.europa.eu

We do not attest that you are compliant. We produce the record that lets someone else decide.

Watchbill™ · watchbill.ai · a product of Blue Jacket Businesses LLC

Disclaimer

This page names the evidence Watchbill™ produces and where it sits in frameworks a reviewer already uses. It concludes nothing about compliance with any framework, standard or law, and it does not say that any system is compliant or certified.