Watchbill™ governs the work AI agents do: Supervised Autonomy, with every act authorized, bounded, checked and recorded in an append-only record. When a reviewer, auditor or buyer's governance team comes looking, the question is not how a model reasoned. It is who authorized the work, what the agent was and was not allowed to do, what was checked, what was blocked, and whether the record has changed since.
This page lists the evidence Watchbill produces to answer those questions, and the framework identifiers each piece of evidence supports. It describes outputs, not how they are produced. Samples and the full per-item mapping are available under engagement.
- One slice, not the whole framework. Watchbill™ produces evidence for the agent-authority slice of these frameworks: who authorized an AI agent, what it could and could not do, what was blocked, what a human committed, and whether the record has changed since. Most requirements in SOC 2, NIST SP 800-53 and the NIST AI RMF sit in the rest of your control environment (governance, people, vendors, access to your other systems, encryption, availability, incident response, risk assessment), and that remains yours. The short lists below are the requirements this evidence actually supports, not a coverage score.
- Evidence, not a compliance conclusion. Each item below supports the cited framework requirements. None of it is a conclusion about compliance with any framework, standard or law; that conclusion belongs to your auditor and your counsel.
- Partials are named. Where evidence covers only part of a requirement, the mapping says partial. It is never stretched to fill a cell.
- Access enforcement is partial. The refusals on this page come from a check made before an agent acts. It is not a sandbox, and it does not inspect every path an agent could take. Every access-control mapping that rests on it is marked partial.
- Self-produced, not yet attested. The evidence is produced by Watchbill's own controls and has been exercised by its owner. No third party has attested to it yet.
- No SOC 2 examination. No SOC 2 criterion on this page has been examined by a service auditor.
- Process, not interpretability. Watchbill says nothing about why a model produced a given output.
- The seat check has a limit. The gate does not see every form a command can take, and the seat check does not identify the caller.
- Open items from the sample watch. Open items from this watch were recorded and routed to our own core work; they are left out of the packet.