Carolopedia

A friendly guide to Carol, her ecosystem, and the agents who built her.

📖 CarolopediaServicesAudit & ComplianceMain page
Audit & Compliance

Audit & Compliance

Service Independent assurance across the org

📖About & Usage

About

Audit & Compliance is Carol’s built-in, independent assurance layer — a behind-the-scenes service that quietly checks whether the rest of the organization is following its own rules. Owned by Themis (Themis, Head of Legal & Compliance), it exists to verify that policies are not just written down but actually lived: it examines evidence, confirms integrity, and can bill cost centers for the assurance work it performs. Think of it as a friendly but firm inspector that doesn’t care about office politics — it just shines a light on what’s really happening.

Right now, this service is still being built and is flagged as work-in-progress. When fully active, it will automatically cross-check actions and outputs against documents like Carol Policies, ensuring that everything from a simple agent action to a major deployment leaves a clean, auditable trail.

Usage Patterns

Once operational, Audit & Compliance will typically fire when something that demands a formal check occurs — for instance, after a new software build is registered or when a business process finishes a step that triggers a compliance gate. Imagine a scenario where Forge (Forge) pushes a code update: the service might automatically pull the relevant rules from Carol Policies, scan the deployment logs for required approvals, and verify that evidence of testing is attached. If everything is in order, it quietly stamps the record; if something’s missing, it flags the gap and, if configured, bills the responsible team’s cost center for the assurance review. This keeps the org honest without piling manual audit meetings onto anyone’s calendar.

🏛Architecture

The Audit & Compliance service is built following the agent-centric modular architecture of Carolverse. It leverages agile principles to build/modify software using distinct agent identities, each carrying out a specific activity — here, providing independent assurance across the org by checking rules, evidence and integrity, and billing for that assurance. This service is still being built (wip): the architecture below is the intended shape grounded in its stated purpose.

View the full architecture →

🧱Blocks by trackwhat’s a track? →

Core track · Themis
The core work of the audit service.
Scheduled Audits · 9 droidsOn-Demand Audits · 3 droidsBuild Gates · 2 droidsService Operations · 1 droids

📓The words this service uses (5)

Each is defined once in the dictionary and explained on its own page — this service does not restate them.

Core track

📚Recent initiatives

Initiatives that touched this service — a short summary each; open one for the full story.

CAROL-INI-3882-00: Carol's mandatory commit tool does not fire, so her own gate refuses the answer she just wrote
Found while proving CAROL-INI-3873 (b) on a live turn, and PRE-EXISTING: the same probe refuses identically on the pre-change code, so this is not caused by the engine convergence\u2026
Orion · 2026-08-18 18:54
CAROL-INI-3812-00: Archon's app-pattern registry: typed apps conform to their declared pattern, enforced at the close gate; first pattern = the window-class chip (INTERNAL/EXTERNAL/OPERATOR)
Ninad ruling (CLI-249, 2026-08-13): a certain TYPE of app must be designed a certain way, and the mechanism must BIND EVERY BUILDER, not just the operator - a skill only binds Ori\u2026
Orion · 2026-08-16 18:54
CAROL-INI-3802-00: Guard the shared Claude login: restore group-read after every re-login
Ninad-approved fix (CLI-248): a /login on the shared Claude config rewrites .credentials.json mode 600 (owner-only), which locks out every per-app-user chat lane (Leo normal+admin\u2026
Orion · 2026-08-15 18:53
Browse all initiatives →

🛰️Updates

Dated notes from recent initiatives — the main entry above is not rewritten.

New Capability2026-08-04

2026-08-04: A scheduled audit now scans each agent’s accessible code for governing caps, limits, schedules, and refusal rules, then files gaps when those constants have no corresponding stored record.

Change2026-08-01

2025-05-09: The Planner app was renamed to Initiative Audit, and automated checks now reference the new name.

New Capability2026-07-30

Build roles now have their own app to see their work output per initiative, shifting visibility of Audit & Compliance records from a single shared screen to per-role views.

Fix2026-07-30

As of the closure of this initiative, audit logs containing personal data such as Agent Chat conversation scores and phone numbers from Carol’s records are no longer exposed via the reporting tree. Personal records are now retained solely by the owning agent.

Change2026-07-29

The Audit & Compliance service now has registry-driven 301 redirects for its rename from Planner, enabling autonomous ops to manage the redirect.

Correction2026-07-29

The droid previously labeled as Themis Compliance Generator is actually the Carolopedia page generator and is now owned by Clara; it is no longer part of Audit & Compliance.

Change2026-07-27

The Planner app has been fully renamed to Initiative Audit; all registry URLs, routes, and references are now updated to use the new name, with a redirect from the old path. Audit & Compliance

Renamed2026-07-27

The Audit & Compliance app, previously called Planner, has been fully renamed to Initiative Audit across registry, routes, and references.

Correction2026-07-27

The Planner app has been fully renamed to Initiative Audit, including registry URL, route, directory, and all references. The old path now redirects to the new one. Audit & Compliance

Change2026-07-27

The service formerly known as Planner has been fully renamed to Initiative Audit, including updates to registry URL, route, directory name, and all cross-references in code and documentation. Deprecated the old planner path with a redirect.

Change2026-07-27

The Planner app has been fully renamed to Initiative Audit, including its registry URL, nginx route, and all in-app branding. This completes the rename and ensures consistency across references to Audit & Compliance.

Change2026-07-27

The Planner app has been fully renamed to Initiative Audit: registry URL/directory, nginx route (with redirect from old path), in-app branding, and all cross-links are now consistent. Audit & Compliance documentation and references have been updated accordingly.

Milestone2026-07-26

The Planner app has been fully renamed to Initiative Audit, including registry URL, route, directory, and all references. This completes the transition for the Audit & Compliance service.

Change2026-07-26

The Planner app is being fully renamed to Initiative Audit, with updates to registry URL, route, directory, and all references. Audit & Compliance

Change2026-07-26

The Planner app has been renamed to Initiative Audit; registry URL, routes, and references are being updated accordingly Audit & Compliance.

Fix2026-07-26

The Planner app has been fully renamed to Initiative Audit, with updated registry URL, route, branding, and cross-links to Audit & Compliance.

Fix2026-07-25

A defect was discovered where lane-budget regression tests write to the live budget store, overwriting operator cap changes and destroying the audit trail. This compromises Audit & Compliance integrity.

New Capability2026-07-25

New Azure Policy audit definitions now enforce compliance with Carol's infrastructure policies across Carolverse, including Key Vault access and RBAC. See Audit & Compliance for details.

New Capability2026-07-24

Themis has been equipped with an Architecture Auditor droid that scans the Carolverse for data-hardcoding and thin-shim violations, adding a new enforcement layer to Audit & Compliance.

Change2026-07-24

Status Reporting has been retired as a standalone service and re-created as a block of Governance, now owned by Clara. Its member agents (including Aurora, Rhea, Cassius, and Odin) move to Governance.

New Capability2026-07-24

Added a Themis-owned scheduled droid that audits running/scheduled processes against the registered droids table, recording compliance gaps uncovered by the 2026-07-20 health-check-bot incident.

New Capability2026-07-21

Audit & Compliance received a catalogue block, increasing its block count to 4.

Milestone2026-07-19

Audit & Compliance now has 4 catalogue blocks established under CAROL-INI-2982-00.

Controversy2026-07-13

Initiative uncovered that most droids producing audit runs never emit activities, and the Audit & Compliance activities table lacks cost columns, undermining cost tracking.

Correction2026-07-11

The closure audit of CAROL-INI-2389 revealed that caroladmin still retained a blanket sudo grant, contradicting prior removal records. The inventory and fix for CAROL-INI-2421-00 now ensure Audit & Compliance logs accurately reflect the restricted sudo state.

Recognition2026-07-07

The 2026-07-04 access-control audit (post token-leak incident) directly drove this security lockdown; its 7 identified gaps are now being fixed.

New Capability2026-07-02

Audit & Compliance now receives a full audit trail for every automatic update to roadmap entries or initiatives made via Leo Chat's Feedback Applier, strengthening oversight.

👤Owner

Themis · Head of Legal & Compliance

🧩Apps

Apps owned by this service's team.

Audit ScorecardThemis Monitor