Audit ledger and receipts
A tamper-evident record of what your organisation asked Ansvar and what came back, which an auditor can verify without access to Ansvar.
Plan Company. Recording starts on its own.
Try it
Using Ansvar, list my audit receipts from 2026-10-01 to 2026-10-07 and verify the receipt for the most recent search.More examples:
Using Ansvar, export the full audit package for our organisation for September 2026 so our auditor can verify it offline.Using Ansvar, list my audit receipts from the last seven days, then decrypt the most recent one and show me what the gateway returned.What comes back
Ansvar writes an encrypted receipt for your organisation's calls and links the receipts so that changing one would break the chain. Each day the chain is co-signed and stamped by an independent timestamp authority, and an export carries everything an auditor needs to check it offline.
For developers, the fields to read:
- Listing: receipt metadata (timestamps, tool names, query ids), paged with
next_cursor - One receipt: its encrypted envelope
- Verification: the chain-hash result and the timestamp authority's signature check (RFC 3161)
- Decryption: the query, the response and metadata
- Export: the full bundle (every encrypted envelope plus anchors, timestamps and signatures; verifies offline) or the summary bundle (metadata and anchors only; does not verify offline). With
include_plaintext=truean org-admin's full export also carries the decrypted content
Which plan
Company. A member reads their own receipts; an org-admin reads the whole organisation's, decrypts receipts and exports the organisation-wide package.
Tools
list_receiptslists receipts for a date range.get_receiptreturns one receipt's encrypted envelope.verify_receiptchecks that a receipt has not been altered.decrypt_receiptdecrypts one receipt (org-admin).export_audit_packageexports receipts for a date range as an audit bundle.
Limits
- Not every tool's full request and response lands in the ledger. Effective-risk results are not stored at Ansvar, and a signed review decision is recorded as metadata only, so keep the results and tokens you need yourself.
- A listing needs a date range. Ansvar never picks the window for you.
- The summary bundle is a view of the record, not evidence. Give an auditor the full bundle.
- An export larger than the response limit is refused with its size, never cut short. Narrow the dates or the scope.
- Decryption and the organisation-wide export are refused for anyone who is not an org-admin, and each decryption is itself recorded.