Use cases· Last updated

Compliance audit trail with Jev

SOC 2 / ISO rows have owners, cadence, and pass/fail. Jev can flag “this evidence blob never mentions production.” The control owner still attests. Jev is not the auditor and not the GRC system of record.

This unofficial page is the audit trail slice of the compliance evidence pre-score pack. Intent: apply the Jev (TypeSafe System One) decision model to compliance evidence pre-score audit trail. Primary search language: Compliance Jev audit trail. Confirm patterns on docs.typesafe.ai. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.

Independent angle (cover ≠ clone): Checklist is the control; Jev pre-scores whether evidence language looks complete. Owner still signs — not a GRC-clone or rival checklist-IA photocopy.

Compliance use-case context

An audit trail for compliance evidence pre-score is a decision trace: replayable inputs, typed answers, floors, and the action the GRC pre-scorer took. It is not a chat log and not a clone of a SIEM product page.

Hub: Use cases. Compare, when the other tool is the real job: compliance checklists.

Audit Trail inputs

Persist the filtered payload (the contract), not whatever arrived at the edge:

{
  "control": { "id": "CC-6.1", "prompt": "Evidence must describe production access reviews this quarter." },
  "evidence": { "title": "Access review export", "text": "We reviewed staging users in January." },
  "policy": { "env": "Staging-only language is a gap for production controls." }
}

Redact secrets before the object hits cold storage.

Decision signals and actions

Minimum fields:

Also store usage.input_tokens (vendor meter) and the full probabilities map — argmax-only logs cannot explain a close mentions_prod.

Do not treat a Noul of 0.5 as a “medium” compliance evidence pre-score score — it means yes and no are equally likely. Conjunctions stay in your code.

Guardrails and escalation

If you cannot explain marking a control passed or signing attestation from the trace, you are not ready to auto-act. TypeSafe’s confidence-gated examples use a lower bar for recoverable reads than for irreversible actions. Those numbers are illustrations. For compliance evidence pre-score, treat mark_control_passed as the high bar (marking a control passed or signing attestation). Tune on labels — see offline evaluation.

Evaluation and rollout notes

Traces are the eval warehouse. Replay against gap / ready / review gold from control owners, plus production-mention gold after criteria or alias changes. Pin jev-1.13.0 (the versioned id) after you fit thresholds. jev-latest and the marketing line jev-1.13 can move. Log the response model. TypeSafe’s published list price for jev-1.13 is $0.042 per million input tokens (vendor claim — confirm on the models page); output tokens are free on that same page. Unused distractors still bill as input.

Official Python and JavaScript SDKs read TYPESAFE_API_KEY and retry documented 429/529. This site does not sell, issue, or proxy TypeSafe keys. Use a credential you already have from the console or a documented gateway.

Pack map

Slice Page
Graph and primitives decision workflow
What may enter state input contracts
What to gather first evidence collection
Atomic rules policy checks
Act / review / abstain confidence thresholds
Reviewer payload human handoff
What to persist you are here
How it breaks failure modes
Labeled replay evaluation
Shadow → canary production rollout

FAQ

Is the HTTP log enough? No. Persist the filtered state, full probabilities, floors, and downstream action as a decision trace.

May I log raw secrets? Redact in code. Jev will not be your DLP layer.

Where is the rest of the Compliance pack? Start with Compliance human handoff and Compliance evaluation. Cluster hub: Use cases.

Can Jev be our auditor? No. It pre-scores language. Owners and auditors sign. See governance.

May we send screenshots? Not as images. Transcribe what the screenshot shows, then ask snap questions.

What this page does not claim

Disclaimer

This is an independent unofficial site and is not affiliated with TypeSafe AI; official documentation is available at https://docs.typesafe.ai.

Primary documentation: https://docs.typesafe.ai. Hub: Use cases.

Sources

Public TypeSafe or adjacent documentation only. No private claims.