Compliance — the evidence, not the certificate.
Standards certify your organization’s management system, not a vendor’s product — Saphan Studio does not come certified, and no tool can make you compliant. What it does is produce, as a by-product of normal operation, the evidence artifacts your auditors ask you for.
The problem, on your calendar
If your organization is certified, your surveillance audit has a date. Adopting AI agents is a material change to a process your management system covers — and it must be reflected there, or the auditor writes it up. The question is not whether to show your agents to the auditor; it is what you will be able to show.
Your ISO certificate has an audit date. Your agents don’t have an evidence trail. Saphan Studio is the missing artifact set — mapped to the controls your auditor already checks.
Where the record is designed to map
ISO/IEC 27001 — change management
Who changed what, on whose approval, with what evidence — the exact questions of the change-management controls, answered per change from the record rather than reconstructed for the audit. Segregation of duties is structural, not declared: implementer, reviewer, and approver are distinct roles with tooling-enforced footprints.
ISO/IEC 27001 — outsourced development
An agent is an outsourced developer in the norm’s sense: work you commission, from a party you must supervise, whose output you must verify before it ships. The protocol is a ready-made supervision regime for exactly that — and this is the mapping your auditor already knows how to check, because the requirement predates AI.
ISO/IEC 42001 — AI management
The AI-management standard asks for governed use of AI with human oversight you can demonstrate. Here oversight is not a policy paragraph: suggestion and decision are separate recorded events, an override is itself a record, and a refusal is durable data. What the standard calls for, the record simply contains.
SOC 2 — change management and processing integrity
Every change carries evidence and a recorded human decision; approvals without proof are unrepresentable. The trail for an audit period renders from the record on demand — Markdown, CSV, PDF, HTML — because every report is a projection of the same record, never a separate truth.
EU AI Act — record-keeping and human oversight
Article 12 asks for records; Article 14 asks for human oversight. In Saphan Studio the record is how the work happens, and oversight is an act with a named actor — not a claim about culture. Both articles are answered by the same mechanism your engineers already use daily.
NIST AI RMF — govern, measure, manage
Policies are named, versioned documents with signed human owners; measurements land on the record next to the work they measure; refusals, overrides, and deviations are data you can query. The framework’s functions stop being aspirations and become columns.
Logging and traceability
The logging and configuration controls — and the traceability clause of ISO 9001 — want to know that the trail exists, is protected, and is complete. Here the trail is append-only, a later edit breaks verification, and access to the management surface is itself logged. Losing an export invalidates nothing, because exports are projections.
One change, traced backward
The audit walkthrough this record supports: start from a merged change and walk it backward — the merge observed on your git, the gate decision with its actor and the evidence it rested on, the review verdict, the order that commissioned the work, the cost booked against its quote. Every link is a record that existed before the question was asked. None of it is assembled after the fact.
That walkthrough is also the honest limit of what we claim: conformity is the auditor’s verdict, not the vendor’s. We say produces the evidence your existing ISMS requires — and never more than that.
More of Saphan Studio
Controls — what is in place, control by control →Enterprise — your machines, your record →Governance — decisions on the record →Security — untrusted agents, provable runs →
Design partner inquiries
Contact us — [email protected]