1. Request mediation that attaches identity and scopes to the request context, with redaction for logs.
  2. Retrieval filtering that enforces access control, source allowlists, and freshness constraints.
  3. Tool mediation that validates schemas, enforces allowlists, and writes audit events for actions.
  4. Output checks that enforce citation rules, restricted data rules, and safe rendering in the user interface.

For agentic systems, tool mediation carries most of the weight. A tool call should pass through a router that enforces permissions, limits targets, and binds idempotency keys to prevent duplicate writes.

Capture evidence as part of normal operation

Audit evidence matters for security, compliance, and internal governance. I aim for evidence that arrives automatically. The system should generate an audit record on each request that includes policy version, model version, prompt version, index version, retrieved sources, tool calls, and final output metadata.

I store this evidence in a system designed for restricted access and retention. It supports incident review and supports periodic reporting. It also supports evaluation work because a team can replay high-impact requests.