SOC 2 evidence
The AI-agent evidence your auditor and customers ask for.
SOC 2 programs already cover human access, change, and monitoring. Use this checklist to extend the same evidence to AI agents.
Why this matters
Customers often request SOC 2 reports to understand how controls are designed and operating. As AI agents gain their own tools and permissions, security teams are asked the same questions about agents that they answer about people.
Without a control layer, those answers are scattered across config, chat, and spreadsheets.
Bakara turns AI-agent capabilities into governed, reviewable, exportable evidence.
The checklist
Evidence to have ready for the audit period.
Access evidence
- Which roles and agents can use each AI skill, tool, and connector?
- Is access aligned to least privilege?
- Who approved each capability?
Change evidence
- What AI capabilities changed during the period?
- Who created, changed, restricted, or blocked them?
- Were changes reviewed?
Monitoring evidence
- Are usage and drift monitored?
- Are risky or unapproved capabilities flagged?
- Is there a review queue?
Review evidence
- Are AI access reviews run on a schedule?
- Do exceptions expire?
- Can you export the review history?
For the full control-theme mapping and an exportable evidence pack, see the SOC 2 evidence page.
Bring AI agents into your SOC 2 program.
Show customers and auditors that your AI agents are approved, monitored, reviewed, and controlled.
Bakara supports AI governance, security operations, and audit-readiness workflows. Regulatory obligations vary by organization, jurisdiction, use case, and implementation. This material is not legal advice.