Managing Audit and Compliance Reports
SailPoint Agent Fabric auditing and compliance reporting provides auditor-ready records for agent inventory, ownership, monitoring, and governance evidence. Admins can generate framework-aligned reports on a scheduled or ad hoc basis, so compliance teams can show governance posture on demand.
Audit and compliance reporting provides:
-
Identity records - Visibility of who owns the agent and what access it has.
-
Action audit trail - Visibility of what the agent did and when.
-
Compliance evidence packaging - Identity governance and action audit trail, packaged into formats external auditors and regulators can consume.
Note
Agent Audit organizes evidence from your SailPoint environment to support your compliance and governance efforts. Evidence reports provided by SailPoint reflect only the data available in SailPoint’s platform and may constitute one part of an overall compliance package. Each report should be reviewed and supplemented by your compliance, legal, or audit teams to confirm sufficiency for a given framework.
Managing Frameworks
Generate reports based upon common frameworks, or create custom frameworks to comply with your organization's compliance requirements.
Select the Status dropdown to filter frameworks by status:
-
Complete - Evidence collection is complete.
-
In Progress - Evidence collection is in progress.
-
Partial - Evidence collection is partially complete due to unavailability of some reports.
-
Not Started - No evidence reports currently available.
Exporting a framework generates all evidence reports associated with the framework.
Exporting a Framework
Generate framework-aligned reports in formats external auditors and regulators can consume.
To export reports for a framework:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Frameworks tab.
-
Select Export on the desired framework to generate and download a zip file to your workstation.
Exported frameworks are also available to view and download on the Export History page.
Adding a Custom Framework
Add a custom framework to comply with your organization's compliance requirements.
To add a custom framework:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Frameworks tab.
-
Select Add Framework.
-
Within the Add Custom Framework window, complete the following fields:
-
In the Framework Name field, enter a name to identify the custom framework.
-
In the Description field, enter a description detailing what the framework is for.
-
In the Evidence Reports field, select the desired reports.
-
-
Select Add Framework.
The framework is available for export from the Frameworks tab.
Deleting a Framework
To delete a framework:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Frameworks tab.
-
Select Delete on the desired framework.
Managing Evidence Reports
Evidence reports include agent, identity, and action audit trail details including:
-
Discovery events, governance decisions, and behavioral detections.
-
Who approved AI agent access rights.
-
Which AI agents process personal data, and where is the record of processing activities.
Select the Category dropdown to filter by report category, or search for reports by report name.
| Evidence Report | Categories | Scope |
|---|---|---|
| Agent Identity Inventory | Monitoring | Inventory of all discovered AI agents with ownership attribution, risk severity classification, agent type categorization (Enterprise, Browser, Endpoint), connector sources, and credential and MCP server connection counts. |
| Application Identity Inventory | Access | Registry of application identities with descriptions, modification timestamps, and owner assignments. |
| Credential Exposure Report | Credential | Inventory of all credentials associated with AI agents and machine identities, including credential type, ownership, source system, creation and expiration dates. |
| Endpoints Report | Monitoring | Inventory of endpoints where AI agents operate, including device names, OS type and version, and discovery source. |
| Governance Action Log | Governance | Inventory of all governance events including machine identity lifecycle actions (create, update, delete), entitlement connections, access changes, and policy enforcement events with actor, target, timestamp, and operation details. |
| Machine Account Inventory | Access | Inventory of all machine accounts (service accounts, service principals, IAM roles) with native identities, sub-type classification, ownership, source and connector attribution, and creation/modification timestamps. |
| MCP Server Inventory | Access | Registry of all MCP servers discovered across managed endpoints with server names, descriptions, last-modified timestamps, ownership attribution, and discovery source. |
| Tools Report | Access | Inventory of all tools available to AI agents with native identity references, modification timestamps, source systems, and connector source. |
Previewing an Evidence Report
Preview evidence reports to view their contents before generating them.
To preview an evidence report:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Evidence Reports tab.
-
Select Preview on the desired evidence report.
A preview of the report is displayed.
Exporting an Evidence Report
Generate evidence reports in formats external auditors and regulators can consume.
To export an individual evidence report:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Evidence Reports tab.
-
Select Export on the desired evidence report to generate and download a zip file to your workstation.
Exported evidence reports are also available to view and download on the Export History page.
To export all evidence reports:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Evidence Reports tab.
-
Select Export All to generate and download a zip file of all reports to your workstation.
Exported evidence reports are also available to view and download on the Export History page.
Viewing Export History
The Export History page lists all previously exported frameworks and evidence reports. Details displayed for each report include:
-
Report - The name of the report.
-
Framework - The framework the report is aligned to.
-
Format - The format the report was generated in.
-
Generated - The timestamp of when the report was generated.
-
Size - The file size of the generated report.
-
Status - Whether the report is:
-
Available - Available for download.
-
In Progress - Currently being generated.
-
Failed - Failed during generation or download.
-
-
Hash - The SHA-256 hash of the complete ZIP binary, allowing user verification that their downloaded zip file is unchanged.
To view details of previously exported frameworks and reports:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Export History tab.
Select Actions
> Download to download the generated framework or report.
Select Actions
> Delete to delete the generated framework or report.
Managing Export Schedules
Schedule the generation of compliance reports for frameworks and evidence reports on a daily, weekly, monthly, quarterly, or semi-annual basis.
To create an export schedule:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Export Schedule tab.
-
In the Name field, enter a name to identify the export schedule.
-
In the Frequency field, select the desired frequency.
-
If you selected Daily, complete the following fields:
-
Time of Day - The time of day the export schedule will run.
-
Start Date - The date the export schedule will first run.
-
Expiration Date - The date the export schedule will no longer run.
-
Frameworks - The frameworks that will be generated by the export schedule.
-
Reports - The evidence reports that will be generated by the export schedule.
-
-
If you selected Weekly, complete the following fields:
-
Day of Week - The day of the week the export schedule will run.
-
Time of Day - The time of day the export schedule will run.
-
Start Date - The date the export schedule will first run.
-
Expiration Date - The date the export schedule will no longer run.
-
Frameworks - The frameworks that will be generated by the export schedule.
-
Reports - The evidence reports that will be generated by the export schedule.
-
-
If you selected Monthly, complete the following fields:
-
Day of Month - The day of the month the export schedule will run.
-
Time of Day - The time of day the export schedule will run.
-
Start Date - The date the export schedule will first run.
-
Expiration Date - The date the export schedule will no longer run.
-
Frameworks - The frameworks that will be generated by the export schedule.
-
Reports - The evidence reports that will be generated by the export schedule.
Note
The export schedule will first run on the configured start date and time of day, and will continue to run on that date and time each month up until the expiration date is reached.
-
-
If you selected Quarterly, complete the following fields:
-
Time of Day - The time of day the export schedule will run.
-
Start Date - The date the export schedule will first run.
-
Expiration Date - The date the export schedule will no longer run.
-
Frameworks - The frameworks that will be generated by the export schedule.
-
Reports - The evidence reports that will be generated by the export schedule.
Note
The export schedule will first run on the configured start date and time of day, and will continue to run on that date and time every 3 months up until the expiration date is reached.
-
-
If you selected Semi-annually, complete the following fields:
-
Time of Day - The time of day the export schedule will run.
-
Start Date - The date the export schedule will first run.
-
Expiration Date - The date the export schedule will no longer run.
-
Frameworks - The frameworks that will be generated by the export schedule.
-
Reports - The evidence reports that will be generated by the export schedule.
Note
The export schedule will first run on the configured start date and time of day, and will continue to run on that date and time every 6 months up until the expiration date is reached.
-
-
-
Select Save Schedule.
The export schedule card is displayed, detailing its configuration.
To edit an export schedule:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Export Schedule tab.
-
Select Edit on the export schedule card you want to edit.
-
Apply the desired changes.
-
Select Update Schedule.
To delete an export schedule:
-
Go to Agentic Fabric > Audit and Compliance.
-
Select the Export Schedule tab.
-
Select Delete on the export schedule card you want to delete.
-
Select Delete to confirm the deletion.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.