Every agent that acts needs an audit trail. Very few need a blockchain. The useful question is which of the two your situation calls for, and the answer depends on who has to trust the record.
What an agent audit trail must answer
When something goes wrong, or someone simply asks, the trail has to answer four questions without re-running the agent: what it read, what it decided, what it changed, and who approved it. If any of the four needs guesswork, the trail is not doing its job.
Re-running is not a substitute. The data has changed since, the model may have been updated, and the second run will not reproduce the first decision. The record has to be written at the time.
Most teams need a central log first
In practice the gap is rarely tamper-proofing. It is that the records exist in several places, in different formats, with nothing tying an agent action to the request that caused it. Fix that first: one log, one schema, every agent action and every human approval written to it as it happens.
A well-run central log with restricted write access, retention rules and regular review covers most internal programmes. It is also what you would build a ledger on top of, if you ever need one.
What has to be logged either side of an agent’s guardrails
When a log is not enough
A log is controlled by whoever runs it. That is fine when the people relying on it are your own people. It stops being fine in three situations.
An outside party has to trust the record
A regulator, a counterparty or the public may need to rely on a record without trusting the organisation that wrote it, or its cloud provider.
The record may be disputed
Where a decision can be challenged, being able to show that an entry has not changed since it was written can matter as much as the entry itself.
The record must outlive the system
Some records have to stay checkable for years, beyond the life of the application, the vendor or the team that built it.
What a ledger adds, and what it does not
A ledger makes entries tamper-evident: anyone with access can check that a record has not been edited since it was written, and when it was written. That is a strong property and a narrow one.
It does not make the agent’s decision correct. A wrong decision recorded on a ledger is a permanently recorded wrong decision. Evaluation, guardrails and human review still do the work of getting the decision right; the ledger only proves what was decided.
Keep the two jobs apart
Guardrails and evaluation make the agent’s decision right. The ledger proves what was decided and when. Neither does the other’s job.
A common and sensible pattern is to keep the full detail in the central log and write only a fingerprint of each important entry, with its time, to the ledger. The log stays searchable, sensitive content stays off the ledger, and anyone can still prove an entry was not changed.
Why ledger nodes belong on more than one cloud
A ledger whose nodes all run in one provider’s account depends on that provider, and on whoever controls the account. Spreading nodes across providers is what turns tamper-evidence into independence, and it keeps the record available when one provider has an incident.
Why agentic AI needs more than one cloud
A three-question test
1. Does anyone outside your organisation need to rely on the record without trusting you? If not, a central log is enough.
2. Could a decision be challenged in a way where proving the record is unchanged matters? If so, consider fingerprints on a ledger.
3. Must the record stay checkable after the system that wrote it is gone? If so, the case for a ledger gets stronger.
No to all three: build the log well. Yes to the first and one other: a ledger alongside the log is worth scoping.
Where Focus20 fits
We design audit trails for agent programmes, starting with the central log and adding a ledger only where the test above says it earns its cost. We are currently providing multi-cloud architecture support to the Maharashtra Pollution Control Board for its agentic AI implementation and blockchain layer.
Read about the MPCB engagement
Questions we get
Does an AI agent need blockchain?
Usually not. Most need a disciplined central log. A ledger is worth adding when outside parties must trust the record without trusting you.
Can a log be tamper-evident without a blockchain?
Partly. Append-only storage, restricted write access and signed entries raise the bar considerably. What they cannot remove is dependence on whoever controls the storage.
What goes on the ledger?
As little as possible: a fingerprint of the entry and its time. Keep personal and sensitive content in the log, where it can be governed and, when required, removed.