Forensics · Evidence capture

Capture evidence with its limits

Versioned adapters record identities, joins, outcomes, digests and access state. Transcript text stays local unless a grant or a managed policy shares it.

For: engineers investigating AI-assisted work, reviewers deciding what the evidence establishes, and team owners checking the same record across devices

What it does, and why it helps

Capture adapters declare which attempt boundaries, parent joins, completion signals, and tool outcomes they support. Real receipts pin adapter and operating-system combinations. Revoking a grant preserves ids and digests but changes later transcript reads to restricted.

The pain. A parser can appear complete while silently guessing relationships its source never records.

The point of view. Every adapter publishes its capability and every receipt keeps the version that produced it.

What gets easier. Knowing whether a missing parent, tool result, or completion is unsupported or absent.

When it helps. Adding a capture source or investigating a cross-agent case.

Its limits. A fixture is not proof of a real install; second-OS acceptance remains an external gate until performed.

Where to find it

  • Desktop: AI incidents, case Evidence and source inspector; Settings shows adapter and delivery health.
  • Hosted: /team/agent-incidents, case Evidence with restricted-source states.
  • API: GET /api/ai-incidents/detail

When to use it

Inspect a real capture receipt

Situation. An AI-assisted change needs an answer that another reviewer can reproduce.

What you do. Open the source inspector and compare adapter version, relationship grades, and completion evidence.

What you see. Observed, inferred, unsupported, and restricted states are named independently.

What it establishes. The case uses only relationships the adapter can substantiate.

Before you start

Supported versions
RepoOps v0.3.1, verified against the 2026-09-17 completion worktree.
Where it runs
The local view needs a tracked repository. The team view needs a bound device and an authenticated team membership.
Permissions
Local evidence follows the repository's own access. Hosted reads are tenant and repository scoped before rows, counts, filters, or exports are built.
Connections
Local inspection works offline. Team delivery needs the device binding and repoops.ai; a failed delivery keeps its cursor and reports the failure.
Plan
Local deterministic analysis is available without a paid runner. Hosted compute, private runners, and model analysis are disabled by default and never silently substituted.

Configure it

  1. Enable capture for the tracked repository and inspect the adapter capability.

    This establishes the scope before any conclusion is computed.

  2. Grant transcript access only for the incident and revoke it after review.

    The receipt records the decision and the evidence ids it used.

SettingWhereA sensible choiceWhy it matters
ⓘ
To stop or undo
Disable the source adapter; queued records remain until their existing delivery policy handles them.

What you should see

A revoked transcript grant

Configuration. Use a tracked repository and leave every unknown or disputed input in its real state.

Expect. The same attempt ids and digests remain, but source text reads restricted.

Verify. The audit row names who read, when, and the grant state without storing the secret.

Data and cost

What is captured
Session and attempt ids, digests, timestamps, adapter/version, relationship and completion grades, tool outcome pointers, and access state.
Who can see it
Without a managed policy, raw text stays local and hosted records contain bounded metadata and pointers under team and repository scope. On a managed repository, an installation that accepted the policy uploads captured Claude Code and Codex transcript source files encrypted, and repository-authorized owners and admins can read and request them until retention ends (see /docs/hosted/team-connect).
How long it is kept
Capture families follow their explicit record-family rules and parent deletion; transcript access follows grant expiry, and managed uploads expire after the policy's retention days.
What leaves the machine
Only enabled redacted families cross the binding.
What it costs
Capture and deterministic parsing are unmetered.

When the result differs

SymptomLikely causeNext action
A parent relationship reads unsupported.The adapter capability for that source/version declares no trustworthy join.Do not infer from timestamps alone; use a source with a supported join or leave it unsupported.
Disable
Stop the relevant capture or prevention toggle in Settings; already recorded evidence remains a historical record.
Roll back
Restore the earlier package version or withdraw the disputed edge. Append the correction; do not rewrite the earlier decision.
Revoke access
Revoke the device or transcript grant. Later reads become restricted while identifiers and non-secret receipts remain auditable.
Delete
Delete the owning case or team through its deletion flow. Prevention groups also expire coherently after 365 days of inactivity.

Maintenance evidence

Feature id
evidence-capture (spine leaf evidence-capture)
Owner
Forensics runtime and public-story owners (LDG-0695 through LDG-0699, LDG-0722)
Supported product version
RepoOps v0.3.1
Last verified
2026-09-17
Example fixtures
Deterministic unit and integration fixtures cited by the source modules; external acceptance gates remain named separately.
Source references
lib/agent-capture.mjs, lib/agent-capture-codex.mjs, lib/incident-source-contract.mjs, lib/transcript-grant.mjs
Documentation review
Claims checked against the implementation and dated evidence. Unknown, disputed, restricted, not-run, and unavailable states are retained.
Video review
No licensed rendered story is published for this guide yet. The guide does not render a placeholder player.

Last updated