1. What the record is designed to establish
For a governed action, Pakkawork can record the workspace, agent and operator identity, immutable contract and hash, arguments after applicable redaction, computed risk, policy result, required approval threshold, human decisions, execution state, verification result, recovery state, and ledger linkage.
That record is designed to answer what was requested, which controls ran, who decided, what the provider reported, what Pakkawork verified, and how the event joins the evidence chain.
2. Integrity and signed evidence
Ledger events are appended to a tenant-serialised sha256 hash chain and signed with Ed25519. This provides technical evidence for detecting later alteration and validating chain continuity when the relevant verification material is available.
A cryptographic signature on a system record is not automatically a qualified electronic signature, notarisation, public timestamp, or court finding under any jurisdiction.
3. Human approvals
Pakkawork records an authenticated approver's decision and pins the required threshold while a request is in flight. Critical actions require two distinct approvers, and an agent cannot approve its own request.
The approval proves the control-plane event recorded by Pakkawork; its legal effect depends on the person's authority, the surrounding facts, applicable law, and the requirements of the organisation relying on it.
4. Governance framework mappings
Pakkawork can map live controls and evidence to topics in the EU AI Act, NIST AI RMF, and ISO/IEC 42001. These mappings help organise a review and identify available evidence.
They do not constitute certification, conformity assessment, legal advice, an audit opinion, or a guarantee that an organisation complies with a framework.
5. Provider and cross-border context
Provider APIs, OAuth scopes, workspace locations, operators, approvers, and affected data may involve different countries and contractual regimes. The workspace remains responsible for determining whether it has authority to connect the provider and perform each action.
Pakkawork's provider-agnostic architecture does not override provider terms, localisation requirements, sanctions, employment rules, records obligations, or data-transfer law.
6. Applicable terms and independent advice
The Terms of Service and any signed order govern the relationship with Pakkawork. A signed order may identify governing law and venue; mandatory rights and obligations may apply regardless of that choice.
Obtain qualified advice for a specific deployment, regulated activity, cross-border transfer, incident, or legal proceeding. Pakkawork supplies technical controls and evidence, not a legal determination.