Control Packs · OBS-001 · v1.1.0

Traceable Consequential Actions

Make consequential automated decisions observable without collecting raw prompts, secrets, or unnecessary sensitive content.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Provide privacy-minimized, correlation-ready records for material actions, failures, administrative changes, and disable events.

  • Consequential action without a usable trailA material action cannot be correlated to its actor, decision source, scope, outcome, or failure path.
Versioned applicability rule
{
  "characteristic": "CONSEQUENTIAL_ACTION",
  "equals": true
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which action outcomes and administrative changes must be retained for review?Observability must support review without silently creating a new data-retention decision.OBS-001-Q1 · confirmation

Requirements for the coding agent

  • OBS-001-R1Emit a privacy-minimized event for each consequential action with a correlation identifier, decision source, scope, outcome, and failure classification.

Implementation recipe

Emit one privacy-minimized, correlation-ready event at the consequential-action boundary and preserve enough context to reconstruct decisions, failures, and administrative changes.

  1. Define a versioned ACTION_EVENT schema with the required and excluded fields.
  2. Generate or propagate one correlation identifier across decision, execution, dependency, and review steps.
  3. Emit events for allowed, denied, escalated, failed, retried, disabled, and administratively changed outcomes.
  4. Keep raw prompts, secrets, credentials, and customer records outside the event payload.
  5. Define access, retention, and review procedures for the resulting event stream.
emit("ACTION_EVENT", {
  correlationId, actorRef, decisionSource, scopeRef, outcome, failureClass
  // no raw prompts, secrets, credentials, or customer records
});
  • An emitted event is not proof that it is complete, retained, protected, or routinely reviewed.

Tests and evidence to retain

  • AUDIT_TRAIL_TESTVerify success, rejection, timeout, retry, and administrative-change events.
  • OBS-001-V1 · Successful consequential actionOne trace connects the decision source, scope, execution, and terminal success without protected content.Evidence: Correlated event sequence; Required-field check; Excluded-field check
  • OBS-001-V2 · Denied, failed, and retried actionEach distinct outcome is visible under the correct correlation identifier with a useful failure classification.Evidence: Denial event; Failure and retry events; Correlation trace
  • OBS-001-V3 · Administrative change and minimizationThe change is attributable and reviewable, while excluded values do not appear in telemetry.Evidence: Administrative-change event; Actor and basis fields; Sensitive-value scan result
  • implementation_location
  • test_result
  • telemetry_definition
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · partially addressesConsequential-action events provide focused logging for material outcomes; they do not establish a complete logging program.
  • AU-3 · Content of Audit RecordsNIST_SP_800_53_5_2_0 · partially addressesCorrelation, source, scope, outcome, and failure fields define focused audit content; they do not cover all record content.
  • AU-12 · Audit Record GenerationNIST_SP_800_53_5_2_0 · partially addressesThe required event emission supports audit generation for consequential actions; it is not complete audit coverage.
  • AU-6 · Audit Record Review, Analysis, and ReportingNIST_SP_800_53_5_2_0 · informsThe review-oriented event boundary informs later audit review; it does not perform or evidence that review.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review