What the machine must be recording before AI touches client files.
You cannot audit what was never written down, and Windows ships with most of it switched off. This checklist names nine things a machine should be recording before an AI assistant is allowed near client files, the question each one answers, and where the setting lives. It is the first layer of ProjxAI Attest, published so you can check your own machines.
Why the defaults are not enough
Process command lines are not recorded. Script blocks are not recorded. Per process network connections are not recorded. The logs that do exist are small enough to wrap before anyone looks. An AI agent runs as the signed in user, so a security tool sees a permitted process reading permitted files and correctly says nothing. The record that answers “what did the AI do” has to be switched on deliberately.
The nine
| Record | The question it answers | Where |
|---|---|---|
| Process creation with full command line | Which agent started which helper, with what instruction | Audit policy: process creation; include command line in events |
| PowerShell script block logging | What a script actually did, not only that it ran | Group Policy: Windows PowerShell, script block logging |
| PowerShell module and transcription logging | The full text of interactive sessions | Group Policy: module logging, transcription to a protected folder |
| Per process network connections | Which process talked to which host, when | Audit filtering platform connection, or a firewall log per process |
| File access at the boundaries that matter | Which files in the client folders were read or changed | Object access auditing on the client file roots only |
| Log size and retention | Whether the record still exists when the question comes | Security, PowerShell and Sysmon logs sized in gigabytes, not megabytes; retention set |
| Time synchronisation | Whether the timestamps can be trusted | Windows Time against a known source; drift logged |
| Recorder start and stop | Whether there are gaps, and when | Log clearing and service stop events retained and alerted |
| Who changed the recording settings | Whether the record was quietly turned down | Audit policy change events retained |
How to use it
- Check each row on one machine that holds client files; most businesses find five or more switched off
- Turn them on, then confirm a week later that they stayed on; drift is common
- Keep the settings in writing beside the AI use policy so a client or insurer can see the intent
- If you cannot keep the record for a tool’s activity, do not use the tool for that purpose
What this does not do
A log is evidence that something happened. It is not a boundary (what AI may read), not attribution (which agent, rather than which process), and not tamper evidence (whether the log was altered afterwards). Those three are the Watcher and the Ledger in ProjxAI Attest, and this checklist is the Recorder they stand on.
Want the machines checked and the record kept for you?
Attest configures the machine, verifies it stayed configured, seals the record and produces one page a month. The boundary conversation is the first hour, at no charge.