Skip to content

Managing Audit and Compliance Reports

SailPoint Agent Fabric auditing and compliance reporting provides auditor-ready records for agent inventory, ownership, monitoring, and governance evidence. Admins can generate framework-aligned reports on a scheduled or ad hoc basis, so compliance teams can show governance posture on demand.

Audit and compliance reporting provides:

  • Identity records - Visibility of who owns the agent and what access it has.

  • Action audit trail - Visibility of what the agent did and when.

  • Compliance evidence packaging - Identity governance and action audit trail, packaged into formats external auditors and regulators can consume.

Note

Agent Audit organizes evidence from your SailPoint environment to support your compliance and governance efforts. Evidence reports provided by SailPoint reflect only the data available in SailPoint’s platform and may constitute one part of an overall compliance package. Each report should be reviewed and supplemented by your compliance, legal, or audit teams to confirm sufficiency for a given framework.

Managing Frameworks

Generate reports based upon common frameworks, or create custom frameworks to comply with your organization's compliance requirements.

Select the Status dropdown to filter frameworks by status:

  • Complete - Evidence collection is complete.

  • In Progress - Evidence collection is in progress.

  • Partial - Evidence collection is partially complete due to unavailability of some reports.

  • Not Started - No evidence reports currently available.

Exporting a framework generates all evidence reports associated with the framework.

Exporting a Framework

Generate framework-aligned reports in formats external auditors and regulators can consume.

To export reports for a framework:

  1. Go to Agentic Fabric > Audit and Compliance > Frameworks.

  2. Find the framework you want to export and select Export.

    Exported frameworks are available to view and download on the Export History page. Refer to Viewing Export History for more information.

Adding a Custom Framework

Add a custom framework to comply with your organization's compliance requirements.

To add a custom framework:

  1. Go to Agentic Fabric > Audit and Compliance > Frameworks.

  2. Select Add Framework.

  3. In the Framework Name field, enter a name to identify the custom framework.

  4. In the Description field, enter a description detailing what the framework is for.

  5. In the Evidence Reports field, select the desired reports.

  6. Select Add Framework.

The framework is available for export from the Frameworks tab.

Deleting a Framework

To delete a framework:

  1. Go to Agentic Fabric > Audit and Compliance > Frameworks.

  2. Find the framework you want to delete and select Delete.

Managing Evidence Reports

Evidence reports include agent, identity, and action audit trail details including:

  • Discovery events, governance decisions, and behavioral detections.

  • Who approved AI agent access rights.

  • Which AI agents process personal data, and where the record of processing activity is located.

Select the Category dropdown to filter by report category, or search for reports by report name.

Evidence Report Categories Scope
Agent Identity Inventory Monitoring Inventory of all discovered AI agents with ownership attribution, risk severity classification, agent type categorization (Enterprise, Browser, Endpoint), connector sources, and credential and MCP client connection counts.
Application Identity Inventory Access Registry of application identities with descriptions, modification timestamps, and owner assignments.
Credential Exposure Report Credential Inventory of all credentials associated with AI agents and machine identities, including credential type, ownership, source system, creation and expiration dates.
Endpoints Report Monitoring Inventory of endpoints where AI agents operate, including device names, OS type and version, and discovery source.
Governance Action Log Governance Inventory of all governance events including machine identity lifecycle actions (create, update, delete), entitlement connections, access changes, and policy enforcement events with actor, target, timestamp, and operation details.
Machine Account Inventory Access Inventory of all machine accounts (service accounts, service principals, IAM roles) with native identities, sub-type classification, ownership, source and connector attribution, and creation/modification timestamps.
MCP Client Inventory Access Registry of all MCP clients discovered across managed endpoints with server names, descriptions, last-modified timestamps, ownership attribution, and discovery source.
Tools Report Access Inventory of all tools available to AI agents with native identity references, modification timestamps, source systems, and connector source.

Previewing an Evidence Report

Preview evidence reports to view their contents before generating them.

To preview an evidence report:

  1. Go to Agentic Fabric > Audit and Compliance > Evidence Reports.

  2. Find the evidence report you want to preview and select Preview.

A preview of the report is displayed.

Exporting an Evidence Report

Generate evidence reports in formats external auditors and regulators can consume.

To export an individual evidence report:

  1. Go to Agentic Fabric > Audit and Compliance.

  2. Select the Evidence Reports tab.

  3. Find the evidence report you want to export and select Export to generate and download a zip file to your workstation.

Exported evidence reports are also available to view and download on the Export History page.

To export all evidence reports:

  1. Go to Agentic Fabric > Audit and Compliance.

  2. Select the Evidence Reports tab.

  3. Select Export All to generate and download a zip file of all reports to your workstation.

Exported evidence reports are also available to view and download on the Export History page.

Viewing Export History

The Export History page lists all previously exported frameworks and evidence reports. You can filter the results by report name, status, and schedule.

Report statuses include:

  • Available - Available for download.

  • In Progress - Currently being generated.

  • Failed - Failed during generation or download.

Downloading Exports

To view your exports, download exported frameworks and evidence reports from the Export History page.

To download exported frameworks and evidence reports:

  1. Go to Agentic Fabric > Audit and Compliance > Export History.

  2. Find the evidence report or framework you want to download and select Actions > Download to download the generated framework or report.

Deleting Exports

You can delete exported frameworks and evidence reports from the Export History page.

To delete exported frameworks and evidence reports:

  1. Go to Agentic Fabric > Audit and Compliance > Export History.

  2. Find the evidence report or framework you want to delete and select Actions > Delete to delete the generated framework or report.

Managing Export Schedules

Schedule the automatic generation of exports for frameworks and evidence reports on a daily, weekly, monthly, quarterly, or semi-annual basis.

To create an export schedule:

  1. Go to Agentic Fabric > Audit and Compliance > Export Schedule.

  2. In the Schedule Name field, enter a name to identify the export schedule.

  3. In the Frequency field, select the desired frequency.

    • If you selected Daily, complete the following fields:

      • Time of Day - Select the time of day the export schedule will run.

      • Start Date - Select or enter the date the export schedule will first run in the MM/DD/YYYY format.

      • Expiration Date - Select or enter the date the export schedule will no longer run in the MM/DD/YYYY format.

      • Frameworks - Select the frameworks that will be generated by the export schedule. You can make multiple selections.

      • Reports - Select the evidence reports that will be generated by the export schedule. You can make multiple selections.

      The export schedule will first run on the configured start date and time of day, and it will continue to run at the scheduled time each day until the expiration date is reached.

    • If you selected Weekly, complete the following fields:

      • Day of Week - Select the day of the week the export schedule will run.

      • Time of Day - Select the time of day the export schedule will run.

      • Start Date - Select or enter the date the export schedule will first run in the MM/DD/YYYY format.

      • Expiration Date - Select or enter the date the export schedule will no longer run in the MM/DD/YYYY format.

      • Frameworks - Select the frameworks that will be generated by the export schedule. You can make multiple selections.

      • Reports - Select the evidence reports that will be generated by the export schedule. You can make multiple selections.

      The export schedule will first run on the configured start date and time of day, and it will continue to run on that day and time each week until the expiration date is reached.

    • If you selected Monthly, complete the following fields:

      • Day of Month - Select the day of the month the export schedule will run.

      • Time of Day - Select the time of day the export schedule will run.

      • Start Date - Select or enter the date the export schedule will first run in the MM/DD/YYYY format.

      • Expiration Date - Select or enter the date the export schedule will no longer run in the MM/DD/YYYY format.

      • Frameworks - Select the frameworks that will be generated by the export schedule. You can make multiple selections.

      • Reports - Select the evidence reports that will be generated by the export schedule. You can make multiple selections.

      The export schedule will first run on the configured start date and time of day, and it will continue to run on that date and time each month until the expiration date is reached.

    • If you selected Quarterly, complete the following fields:

      • Time of Day - Select the time of day the export schedule will run.

      • Start Date - Select or enter the date the export schedule will first run in the MM/DD/YYYY format.

      • Expiration Date - Select or enter the date the export schedule will no longer run in the MM/DD/YYYY format.

      • Frameworks - Select the frameworks that will be generated by the export schedule. You can make multiple selections.

      • Reports - Select the evidence reports that will be generated by the export schedule. You can make multiple selections.

      The export schedule will first run on the configured start date and time of day, and it will continue to run on the same day of the month and time every 3 months until the expiration date is reached.

    • If you selected Semi-annually, complete the following fields:

      • Time of Day - Select the time of day the export schedule will run.

      • Start Date - Select or enter the date the export schedule will first run in the MM/DD/YYYY format.

      • Expiration Date - Select or enter the date the export schedule will no longer run in the MM/DD/YYYY format.

      • Frameworks - Select the frameworks that will be generated by the export schedule. You can make multiple selections.

      • Reports - Select the evidence reports that will be generated by the export schedule. You can make multiple selections.

      The export schedule will first run on the configured start date and time of day, and it will continue to run on the same day of the month and time every 6 months until the expiration date is reached.

  4. Select Save Schedule.

The export schedule card is displayed, detailing its configuration.

To edit an export schedule:

  1. Go to Agentic Fabric > Audit and Compliance > Export Schedule.

  2. Select Edit on the export schedule card you want to edit.

  3. Apply the desired changes.

  4. Select Update Schedule.

To delete an export schedule:

  1. Go to Agentic Fabric > Audit and Compliance > Export Schedule.

  2. Select Delete on the export schedule card you want to delete.

  3. Select Delete to confirm the deletion.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.