Control Packs · OBS-001 · v1.1.0
Traceable Consequential Actions
Make consequential automated decisions observable without collecting raw prompts, secrets, or unnecessary sensitive content.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Provide privacy-minimized, correlation-ready records for material actions, failures, administrative changes, and disable events.
- Consequential action without a usable trailA material action cannot be correlated to its actor, decision source, scope, outcome, or failure path.
Versioned applicability rule
{
"characteristic": "CONSEQUENTIAL_ACTION",
"equals": true
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which action outcomes and administrative changes must be retained for review?Observability must support review without silently creating a new data-retention decision.OBS-001-Q1 · confirmation
Requirements for the coding agent
- OBS-001-R1Emit a privacy-minimized event for each consequential action with a correlation identifier, decision source, scope, outcome, and failure classification.
Implementation recipe
Emit one privacy-minimized, correlation-ready event at the consequential-action boundary and preserve enough context to reconstruct decisions, failures, and administrative changes.
- Define a versioned ACTION_EVENT schema with the required and excluded fields.
- Generate or propagate one correlation identifier across decision, execution, dependency, and review steps.
- Emit events for allowed, denied, escalated, failed, retried, disabled, and administratively changed outcomes.
- Keep raw prompts, secrets, credentials, and customer records outside the event payload.
- Define access, retention, and review procedures for the resulting event stream.
emit("ACTION_EVENT", {
correlationId, actorRef, decisionSource, scopeRef, outcome, failureClass
// no raw prompts, secrets, credentials, or customer records
});- An emitted event is not proof that it is complete, retained, protected, or routinely reviewed.
Tests and evidence to retain
- AUDIT_TRAIL_TESTVerify success, rejection, timeout, retry, and administrative-change events.
- OBS-001-V1 · Successful consequential actionOne trace connects the decision source, scope, execution, and terminal success without protected content.Evidence: Correlated event sequence; Required-field check; Excluded-field check
- OBS-001-V2 · Denied, failed, and retried actionEach distinct outcome is visible under the correct correlation identifier with a useful failure classification.Evidence: Denial event; Failure and retry events; Correlation trace
- OBS-001-V3 · Administrative change and minimizationThe change is attributable and reviewable, while excluded values do not appear in telemetry.Evidence: Administrative-change event; Actor and basis fields; Sensitive-value scan result
- implementation_location
- test_result
- telemetry_definition
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · partially addressesConsequential-action events provide focused logging for material outcomes; they do not establish a complete logging program.
- AU-3 · Content of Audit RecordsNIST_SP_800_53_5_2_0 · partially addressesCorrelation, source, scope, outcome, and failure fields define focused audit content; they do not cover all record content.
- AU-12 · Audit Record GenerationNIST_SP_800_53_5_2_0 · partially addressesThe required event emission supports audit generation for consequential actions; it is not complete audit coverage.
- AU-6 · Audit Record Review, Analysis, and ReportingNIST_SP_800_53_5_2_0 · informsThe review-oriented event boundary informs later audit review; it does not perform or evidence that review.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.