Tools · Governance starter set · 3 of 3

What the machine must be recording before AI touches client files.

You cannot audit what was never written down, and Windows ships with most of it switched off. This checklist names nine things a machine should be recording before an AI assistant is allowed near client files, the question each one answers, and where the setting lives. It is the first layer of ProjxAI Attest, published so you can check your own machines.

ChecklistReviewed 4 September 2026Windows 10 and 11No email asked for
01

Why the defaults are not enough

Process command lines are not recorded. Script blocks are not recorded. Per process network connections are not recorded. The logs that do exist are small enough to wrap before anyone looks. An AI agent runs as the signed in user, so a security tool sees a permitted process reading permitted files and correctly says nothing. The record that answers “what did the AI do” has to be switched on deliberately.

02

The nine

Process creation with full command line
The question it answers
Which agent started which helper, with what instruction
Where
Audit policy: process creation; include command line in events
PowerShell script block logging
The question it answers
What a script actually did, not only that it ran
Where
Group Policy: Windows PowerShell, script block logging
PowerShell module and transcription logging
The question it answers
The full text of interactive sessions
Where
Group Policy: module logging, transcription to a protected folder
Per process network connections
The question it answers
Which process talked to which host, when
Where
Audit filtering platform connection, or a firewall log per process
File access at the boundaries that matter
The question it answers
Which files in the client folders were read or changed
Where
Object access auditing on the client file roots only
Log size and retention
The question it answers
Whether the record still exists when the question comes
Where
Security, PowerShell and Sysmon logs sized in gigabytes, not megabytes; retention set
Time synchronisation
The question it answers
Whether the timestamps can be trusted
Where
Windows Time against a known source; drift logged
Recorder start and stop
The question it answers
Whether there are gaps, and when
Where
Log clearing and service stop events retained and alerted
Who changed the recording settings
The question it answers
Whether the record was quietly turned down
Where
Audit policy change events retained
03

How to use it

  • Check each row on one machine that holds client files; most businesses find five or more switched off
  • Turn them on, then confirm a week later that they stayed on; drift is common
  • Keep the settings in writing beside the AI use policy so a client or insurer can see the intent
  • If you cannot keep the record for a tool’s activity, do not use the tool for that purpose
04

What this does not do

A log is evidence that something happened. It is not a boundary (what AI may read), not attribution (which agent, rather than which process), and not tamper evidence (whether the log was altered afterwards). Those three are the Watcher and the Ledger in ProjxAI Attest, and this checklist is the Recorder they stand on.

Want the machines checked and the record kept for you?

Attest configures the machine, verifies it stayed configured, seals the record and produces one page a month. The boundary conversation is the first hour, at no charge.