Back to blogCompliance

Who Approved That? The Audit Trail Your AI Agents Are Missing

Camunda 8.9 adds a centralized audit log and A2A connectors. What they record, where configuration matters, and what to check before a regulated deployment.

Diagram of a business process

An external auditor asks: “The agent approved this request—who reviewed it, and against which rule?” If the answer is “the agent just decided,” the team cannot substantiate the decision. That is an operational problem and may also be a compliance issue.

As agents move from conversation to action—updating a customer record, helping assess credit, or opening a claim—traceable decisions matter more. Camunda 8.9 adds capabilities relevant to that work. For a regulated Israeli organization, the key is to understand both what the platform records and what the implementation must supply.

What is new in Camunda 8.9

Camunda 8.9 introduces a centralized audit log for supported operations across process, identity, and user-task domains. The audit-log documentation describes records of who performed an operation, when, and on which entity. These records can support an audit, but they are not a complete account of an AI model’s reasoning or every action in an external system.

The audit log has several properties that matter to a regulated organization:

  • API access: audit records are available through the Orchestration Cluster REST API for integration with reporting and governance systems.
  • Operational interfaces: records are available in Operate, Tasklist, and Admin, formerly Orchestration Cluster Identity.
  • Access controls: permissions determine who can view audit records.
  • Configurable capture: actor types and operations can be selected. Crucially, the documented default tracks user operations, not client operations. Check coverage for the identities your agents and connectors actually use.

The release also adds A2A (Agent-to-Agent) client connectors to discover remote agents, send messages, and retrieve responses. However, the 8.9 documentation lists these under alpha features and states that authentication against a remote A2A server is not currently supported. Do not treat protocol support as a guarantee of signed messages, authenticated remote access, or complete cross-agent evidence. Security, correlation, and escalation paths need explicit design and validation.

Why this matters for a regulated Israeli organization

For a sensitive banking or insurance workflow, start with the evidence your risk and compliance teams need: the case identifier, actor, applicable policy version, action, approval, and outcome. Map these requirements to the systems involved. A Camunda operation record may need to be joined with application, identity-provider, and external-agent records to explain the full case.

Israel’s Privacy Protection Authority guidance on Regulation 10 applies access-logging requirements to databases subject to medium or high security levels. It describes recording identity, time, the system component, access type and scope, and whether access was allowed or denied. That is more specific than a general instruction to log AI activity. A process audit log alone may not cover database access or all required events.

Treat the audit log as one part of the control design. Verify coverage, retention, protection against alteration, and authorized access against the requirements for your system. The feature itself is not regulatory approval and does not make evidence automatically legally admissible.

What this means for your organization

If you are considering AI agents in a sensitive process - credit, claims, customer service with financial impact - ask three questions before deployment:

  1. Can we reconstruct a case? Check how agent actions, human approvals, policy versions, and external-system events are linked.
  2. Can authorized reviewers retrieve the evidence? Agree on a repeatable export or query, with access controls and a responsible owner. Needing a query is not itself a failure; missing or inaccessible evidence is.
  3. What happens when one agent invokes another? Verify identities, permissions, correlation identifiers, failures, and the records retained on both sides.

This is exactly the approach we advocate at NG Workshop: AI that works within the process, not instead of it - so documentation, control, and permissions are part of the architecture from day one, not something bolted on after a regulator asks a question. We covered the separation between agent and process engine in AI Agents Need a Conductor, and the balance between automation and human oversight in Human-in-the-Loop as Governance.

Sources

Summary

  • Camunda 8.9 provides a centralized log of supported operations, accessible through APIs and operational tools.
  • Capture settings matter: client operations are not logged by default, and A2A support has documented limits.
  • Audit readiness requires evidence across the whole process, with controls matched to the organization’s obligations.

Want to assess your organization’s readiness for governed AI agents? Let’s talk

Audit TrailComplianceAI AgentsCamundaGovernanceBanking

Ready to upgrade your business processes?

Let’s talk. A free initial consultation where we learn your needs and see how technology can serve you.

Start a WhatsApp chatFast response on WhatsApp — no commitment
or
We’ll get back to you within one business day.