Forensics · Evidence export
Export evidence another reviewer can verify
Create a bounded proof pack with source ids, digests, versions, scope, and verification instructions instead of a screenshot-only claim.
For: engineers investigating AI-assisted work, reviewers deciding what the evidence establishes, and team owners checking the same record across devices
What it does, and why it helps
The pain. Screenshots lose scope, provenance, and the records excluded from a conclusion.
The point of view. An export is useful when an independent reviewer can recompute it.
What gets easier. Handing a control, incident, or recurrence decision to security, compliance, or another team.
When it helps. A case closes, a prevention package publishes, or an audit asks how a metric was computed.
Its limits. A signature authenticates the issuer and bytes, not the truth of a human judgment.
Where to find it
- Desktop: Governance and the AI incident case export controls.
- Hosted: /team/production-evidence and the case evidence export.
- API:
GET /api/audit-export/pubkey
When to use it
Produce a case proof pack
Situation. An AI-assisted change needs an answer that another reviewer can reproduce.
What you do. Export the case after evidence, attribution, decision, and prevention receipts are complete.
What you see. The pack includes stable ids, digests, scope, versions, unknown/disputed states, and verification instructions.
What it establishes. Another reviewer can validate integrity and recount derived cells without receiving restricted transcript text.
Before you start
- Supported versions
- RepoOps v0.3.1, verified against the 2026-09-17 completion worktree.
- Where it runs
- The local view needs a tracked repository. The team view needs a bound device and an authenticated team membership.
- Permissions
- Local evidence follows the repository's own access. Hosted reads are tenant and repository scoped before rows, counts, filters, or exports are built.
- Connections
- Local inspection works offline. Team delivery needs the device binding and repoops.ai; a failed delivery keeps its cursor and reports the failure.
- Plan
- Local deterministic analysis is available without a paid runner. Hosted compute, private runners, and model analysis are disabled by default and never silently substituted.
Configure it
- Resolve the exact case and repository scope.
This establishes the scope before any conclusion is computed.
- Generate the export and verify its signature and included source receipts.
The receipt records the decision and the evidence ids it used.
| Setting | Where | A sensible choice | Why it matters |
|---|
What you should see
A verifiable restricted export
Configuration. Use a tracked repository and leave every unknown or disputed input in its real state.
Expect. The pack contains the grant-protected evidence pointer and digest, not the source body.
Verify. Signature verification passes and the access field remains restricted.
Data and cost
- What is captured
- Selected case records, evidence pointers, digests, definition versions, scope, receipts, and signature metadata.
- Who can see it
- The operator chooses where the downloaded pack goes; RepoOps does not upload it as part of export.
- How long it is kept
- The generated download is controlled by the operator; source records keep their normal retention and deletion rules.
- What leaves the machine
- None during local generation. A recipient gets only what the pack contains when the operator sends it.
- What it costs
- Generation and verification are deterministic and unmetered.
When the result differs
| Symptom | Likely cause | Next action |
|---|---|---|
| A recipient cannot verify the export. | The public key, signature, or exact exported bytes do not match. | Fetch the issuer public key from the documented endpoint and verify the untouched file; regenerate rather than editing it. |
- Disable
- Stop the relevant capture or prevention toggle in Settings; already recorded evidence remains a historical record.
- Roll back
- Restore the earlier package version or withdraw the disputed edge. Append the correction; do not rewrite the earlier decision.
- Revoke access
- Revoke the device or transcript grant. Later reads become restricted while identifiers and non-secret receipts remain auditable.
- Delete
- Delete the owning case or team through its deletion flow. Prevention groups also expire coherently after 365 days of inactivity.
Related tasks
Maintenance evidence
- Feature id
evidence-export(spine leafevidence-export)- Owner
- Forensics runtime and public-story owners (LDG-0695 through LDG-0699, LDG-0722)
- Supported product version
- RepoOps v0.3.1
- Last verified
- 2026-09-17
- Example fixtures
- Deterministic unit and integration fixtures cited by the source modules; external acceptance gates remain named separately.
- Source references
lib/compliance/evidence-pack.mjs,lib/launch-plan/evidence.mjs,website/app/api/audit-export/pubkey/route.ts,website/app/team/(home)/production-evidence/page.tsx- Documentation review
- Claims checked against the implementation and dated evidence. Unknown, disputed, restricted, not-run, and unavailable states are retained.
- Video review
- No licensed rendered story is published for this guide yet. The guide does not render a placeholder player.
Last updated