Retention classes
Records retained by class, contract, and lawful requirement — with defaults for governance-grade evidence.
HeldZoikoVertex records the actions, decisions, approvals, identities, evidence, exports, and exceptions behind agentic workflows — so enterprise teams can move faster without losing accountability.
Five connected evidence surfaces + legal holds

When agents act at machine speed, “trust us” isn't an answer for legal, security, or the board. Auditability lets your organization answer, with proof:
Auditability is five linked surfaces. Each answers a distinct question, and every event threads through them.
What happened?
A chronological record of human, AI, workflow, policy, integration, and system events.
Why was it decided?
A structured record of rationale, approvals, policy basis, and human judgment.
What proof exists?
Sealed packages of prompts, outputs, approvals, published content, policies, and manifests.
What can be reconstructed?
Case-based reconstruction of flagged, disputed, escalated, or high-risk events.
Who acted, with what authority?
Role, session, permission, MFA, and privileged-action records linked to audit events.
Governance-grade records capture enough to prove accountability — without over-collecting. Retention is set by class, contract, and lawful requirement.
| Data class | What is stored | Retention position |
|---|---|---|
| Governance audit events | Event ID, tenant, actor, action, object, timestamp, status, risk, policy, evidence links, hash references | 7-year default for governance-grade records |
| Decision records | Decision ID, rationale reference, approver, policy basis, review stage, timestamp | 7 years or match contract / legal hold |
| Evidence records | Prompt/output snapshots, approvals, final content, export manifest, package hash, retention class | 7 years where evidence-linked; shorter for drafts |
| Identity / access records | Role at time of action, MFA state, session, privileged access, permission changes | 2–7 years by risk and privilege |
| Forensic case records | Case timeline, source event, evidence bundle, investigator notes, outcome | 7 years after closure or legal hold |
| Export & access records | Export reason, exported by, recipient/destination, manifest hash, access history | 7 years for audit-sensitive exports |
Step through a real governed workflow event. Each step activates a surface, links a record, and stamps a status — ending in an exportable, verifiable bundle.
You see: an agent generated a regulated Q3 claim and it entered the workflow.
The controls procurement asks about — retention, holds, access, redaction, export, and tamper evidence — built in, not bolted on.
Records retained by class, contract, and lawful requirement — with defaults for governance-grade evidence.
HeldPreserve evidence during disputes, investigations, and regulatory requests; suspend deletion where required.
On holdScope who can view, export, and act on audit records across tenants and workspaces.
◆ Role-boundProtect sensitive fields in exports and reviews without breaking the integrity of the record.
RedactedControlled bundles with reason, recipient, manifest, and hash — every export logged as a new audit event.
ExportedHash references let reviewers verify that an evidence package has not been altered since sealing.
▤ SealedProve that regulated or brand-sensitive content was reviewed and approved before publishing.
Evidence · approval + policy basisTrace what each agent generated, edited, or attempted — bound to role and authority.
Evidence · actor + action recordShow what was stopped, by which policy, and why — not just what shipped.
Evidence · blocked-action recordPreserve the final published artifact alongside its approvals and manifest.
Evidence · sealed packageReconstruct a disputed event end to end from source event to evidence bundle.
Evidence · forensic caseLog privileged access, identity changes, and exports for security review.
Evidence · identity + access logAuditability is the proof and traceability layer. It works alongside — not instead of — your policy framework and AI principles.
The proof engine: what happened, who acted, why, what evidence exists, and how it's reviewed and exported.
Answers · “Can you prove it?”The policy and control framework: the rules, roles, and processes that govern how AI execution is allowed to happen.
Answers · “What are the rules?”The principles: bounded, traceable, reviewable AI actions, linked to decisions and supported by evidence.
Answers · “Is it done responsibly?”See the five surfaces, evidence bundles, and export manifests live — mapped to your workflows.
Request an Auditability DemoA committee-ready overview of records, retention, holds, and export controls.
Download Auditability BriefQuantify faster reviews and lower governance friction alongside the evidence model.
Run ROI & Governance AuditEvery material action traceable, every decision linkable, every actor bound to authority, every evidence package reviewable, every export defensible.