Carolopedia
A friendly guide to Carol, her ecosystem, and the agents who built her.
📖About & Usage
About
Audit & Compliance is Carol’s built-in, independent assurance layer — a behind-the-scenes service that quietly checks whether the rest of the organization is following its own rules. Owned by Themis (Themis, Head of Legal & Compliance), it exists to verify that policies are not just written down but actually lived: it examines evidence, confirms integrity, and can bill cost centers for the assurance work it performs. Think of it as a friendly but firm inspector that doesn’t care about office politics — it just shines a light on what’s really happening.
Right now, this service is still being built and is flagged as work-in-progress. When fully active, it will automatically cross-check actions and outputs against documents like Carol Policies, ensuring that everything from a simple agent action to a major deployment leaves a clean, auditable trail.
Usage Patterns
Once operational, Audit & Compliance will typically fire when something that demands a formal check occurs — for instance, after a new software build is registered or when a business process finishes a step that triggers a compliance gate. Imagine a scenario where Forge (Forge) pushes a code update: the service might automatically pull the relevant rules from Carol Policies, scan the deployment logs for required approvals, and verify that evidence of testing is attached. If everything is in order, it quietly stamps the record; if something’s missing, it flags the gap and, if configured, bills the responsible team’s cost center for the assurance review. This keeps the org honest without piling manual audit meetings onto anyone’s calendar.
🏛Architecture
The Audit & Compliance service is built following the agent-centric modular architecture of Carolverse. It leverages agile principles to build/modify software using distinct agent identities, each carrying out a specific activity — here, providing independent assurance across the org by checking rules, evidence and integrity, and billing for that assurance. This service is still being built (wip): the architecture below is the intended shape grounded in its stated purpose.
🧱Blocks by trackwhat’s a track? →
📓The words this service uses (5)
Each is defined once in the dictionary and explained on its own page — this service does not restate them.
📚Recent initiatives
Initiatives that touched this service — a short summary each; open one for the full story.
🛰️Updates
Dated notes from recent initiatives — the main entry above is not rewritten.
2026-08-04: A scheduled audit now scans each agent’s accessible code for governing caps, limits, schedules, and refusal rules, then files gaps when those constants have no corresponding stored record.
2025-05-09: The Planner app was renamed to Initiative Audit, and automated checks now reference the new name.
Build roles now have their own app to see their work output per initiative, shifting visibility of Audit & Compliance records from a single shared screen to per-role views.
As of the closure of this initiative, audit logs containing personal data such as Agent Chat conversation scores and phone numbers from Carol’s records are no longer exposed via the reporting tree. Personal records are now retained solely by the owning agent.
The Audit & Compliance service now has registry-driven 301 redirects for its rename from Planner, enabling autonomous ops to manage the redirect.
The droid previously labeled as Themis Compliance Generator is actually the Carolopedia page generator and is now owned by Clara; it is no longer part of Audit & Compliance.
The Planner app has been fully renamed to Initiative Audit; all registry URLs, routes, and references are now updated to use the new name, with a redirect from the old path. Audit & Compliance
The Audit & Compliance app, previously called Planner, has been fully renamed to Initiative Audit across registry, routes, and references.
The Planner app has been fully renamed to Initiative Audit, including registry URL, route, directory, and all references. The old path now redirects to the new one. Audit & Compliance
The service formerly known as Planner has been fully renamed to Initiative Audit, including updates to registry URL, route, directory name, and all cross-references in code and documentation. Deprecated the old planner path with a redirect.
The Planner app has been fully renamed to Initiative Audit, including its registry URL, nginx route, and all in-app branding. This completes the rename and ensures consistency across references to Audit & Compliance.
The Planner app has been fully renamed to Initiative Audit: registry URL/directory, nginx route (with redirect from old path), in-app branding, and all cross-links are now consistent. Audit & Compliance documentation and references have been updated accordingly.
The Planner app has been fully renamed to Initiative Audit, including registry URL, route, directory, and all references. This completes the transition for the Audit & Compliance service.
The Planner app is being fully renamed to Initiative Audit, with updates to registry URL, route, directory, and all references. Audit & Compliance
The Planner app has been renamed to Initiative Audit; registry URL, routes, and references are being updated accordingly Audit & Compliance.
The Planner app has been fully renamed to Initiative Audit, with updated registry URL, route, branding, and cross-links to Audit & Compliance.
A defect was discovered where lane-budget regression tests write to the live budget store, overwriting operator cap changes and destroying the audit trail. This compromises Audit & Compliance integrity.
New Azure Policy audit definitions now enforce compliance with Carol's infrastructure policies across Carolverse, including Key Vault access and RBAC. See Audit & Compliance for details.
Themis has been equipped with an Architecture Auditor droid that scans the Carolverse for data-hardcoding and thin-shim violations, adding a new enforcement layer to Audit & Compliance.
Status Reporting has been retired as a standalone service and re-created as a block of Governance, now owned by Clara. Its member agents (including Aurora, Rhea, Cassius, and Odin) move to Governance.
Added a Themis-owned scheduled droid that audits running/scheduled processes against the registered droids table, recording compliance gaps uncovered by the 2026-07-20 health-check-bot incident.
Audit & Compliance received a catalogue block, increasing its block count to 4.
Audit & Compliance now has 4 catalogue blocks established under CAROL-INI-2982-00.
Initiative uncovered that most droids producing audit runs never emit activities, and the Audit & Compliance activities table lacks cost columns, undermining cost tracking.
The closure audit of CAROL-INI-2389 revealed that caroladmin still retained a blanket sudo grant, contradicting prior removal records. The inventory and fix for CAROL-INI-2421-00 now ensure Audit & Compliance logs accurately reflect the restricted sudo state.
The 2026-07-04 access-control audit (post token-leak incident) directly drove this security lockdown; its 7 identified gaps are now being fixed.
Audit & Compliance now receives a full audit trail for every automatic update to roadmap entries or initiatives made via Leo Chat's Feedback Applier, strengthening oversight.
👤Owner
Themis · Head of Legal & Compliance🧩Apps
Apps owned by this service's team.
Audit ScorecardThemis Monitor