Intent-Based Governance · 5 of 5L2paper
Governance at Scale: Intent Ledgers, Audit Trails, and Mapping to NIST AI RMF and the EU AI Act
One agent's intent is a design detail; a fleet's intents are a governance system — and it only holds together when every declared intent and every decision becomes durable, queryable, auditable evidence.
Abstract
Intent-based governance works for a single agent when the intent is captured, enforced, and measured; it works for a fleet only when the intents themselves become a managed system of record. This article develops governance at scale. It introduces the intent ledger — an append-only record of every declared intent, its provenance and version, and the governance decisions and conformance results tied to it — and the audit trail that makes any decision traceable end to end. It then maps this machinery onto the governance frameworks a serious deployment must answer to: the NIST AI Risk Management Framework's functions, the record-keeping and documentation obligations of the EU AI Act, and the management-system expectations of ISO/IEC 42001. The key takeaway is that at scale the ledger is not overhead but the product: it converts 'we govern our agents by intent' from an assertion into standing, queryable evidence, and its completeness and integrity are what make fleet-wide intent governance real rather than aspirational.
A single agent's declared intent is something you can hold in your head — one goal, a handful of constraints, a scope. A fleet's intents are something else entirely: thousands of declarations, each versioned, each producing a stream of governance decisions and conformance results, changing continuously as tasks come and go. At that scale the question stops being 'is this action on-intent?' and becomes 'can we, at any moment, say which intents govern our fleet, whether each is being honored, and prove it to someone who asks?' Answering that requires treating intents not as ephemeral runtime objects but as a durable, queryable system of record — a ledger of intents and the decisions they drove, and an audit trail that ties any outcome back to the intent that authorized it. This article builds that record and then shows how it becomes the evidence that regulatory and management frameworks actually require.
From One Intent to Many
The move from governing one agent to governing a fleet is a change in kind, because fleet-level questions depend on properties no single-agent mechanism provides. Can we enumerate every intent currently governing an agent? Which intents share a constraint, so that a policy change touches all of them? Which agents are operating under an intent whose conformance has been degrading? None of these can be answered by a runtime that evaluates one action against one intent and forgets both; they require the intents and their outcomes to be recorded, related, and queryable across the whole population.
This is the same completeness demand that governs identity at scale, applied to intent: a governance system you cannot fully enumerate is one you cannot trust, because the intents you have lost track of are exactly the ungoverned ones. An intent that governed an agent yesterday but left no durable record leaves a hole in the account — a period of behavior that was governed by a standard no longer inspectable. Fleet governance therefore begins with the discipline that every declared intent, and every decision it produced, is written to a record that outlives the task.
The framing that organizes the rest of this article is that the record is the governance. At small scale the governance feels like the runtime checks; at fleet scale the runtime checks are transient and the durable artifact — the ledger of intents and decisions — is what a team, an auditor, or a regulator actually interacts with. Building that artifact well is not administrative overhead layered on top of governance; it is the form governance takes once there is more of it than any person can hold in mind.
The Intent Ledger
The intent ledger is an append-only record of every declared intent and everything that happened under it. Each entry binds an intent to its provenance and version — who declared it, signed how, at which version — so that any later question about what governed an agent has a definite answer. To each intent the ledger attaches the governance decisions it produced (which actions were allowed, denied, or escalated) and the conformance results measured against it (completeness and minimality over the trajectories it governed). The ledger is thus not a list of intents but a graph relating intents to their versions, decisions, and outcomes.
Append-only is the essential property, because a governance record that can be edited after the fact is a governance record that can be made to lie. The point of the ledger is to be trustworthy testimony about what standard governed which behavior and what the governance concluded, and that testimony is only worth anything if it cannot be rewritten to match a preferred story. Entries are added, never altered; a correction is a new entry, not an overwrite, so the history of the governance is itself preserved. This is the same integrity discipline that makes any audit log meaningful, applied to the specific content of intent governance.
The ledger's value grows with the questions it can answer, and those questions are precisely the fleet-level ones. Enumerate all active intents. Find every intent that shares a given constraint. Trace an agent's behavior over a week to the sequence of intents that governed it. Surface intents whose conformance has trended downward. Each is a query against the ledger, and each is unanswerable without it. Designing the ledger is largely designing for these queries — recording enough structure that the questions a governance team, an incident responder, or an auditor will ask are answerable by reading the record rather than reconstructing it.
The Audit Trail
Where the ledger is the standing record, the audit trail is the thread that makes any single outcome explicable end to end. For a given action an agent took, the audit trail should let a reviewer walk backward through the complete chain: the action, the governance decision that permitted or flagged it, the compiled rule that produced the decision, the intent version that compiled to that rule, and the provenance that authenticated the intent. A governance decision a reviewer cannot trace to the intent that justified it is a decision they cannot assess, which is why the trail must be continuous — every link recorded, with no step taken on faith.
Continuity is what distinguishes an audit trail from a mere log. A log that records decisions without linking them to the intents and rules behind them tells you what happened but not why it was permitted, and 'why it was permitted' is exactly the governance question. The trail is the causal chain, and its completeness is a hard requirement: a break anywhere — a decision whose governing intent version was not recorded, an action whose decision was not logged — is a point at which the account fails and the behavior becomes unexplainable after the fact. The EU AI Act's record-keeping and logging obligations for high-risk AI systems are, in substance, a demand for exactly this kind of traceability, and a continuous audit trail is how an intent-governed system meets it.
The trail also runs forward, from an intent to its consequences. Given an intent — say, one later found to be flawed — the trail should surface every decision it drove and every action taken under it, so that the blast radius of a bad intent can be assessed and, where necessary, remediated. This bidirectional traceability, backward from an action to its justification and forward from an intent to its effects, is what turns the ledger from a passive archive into an instrument of governance: it is how you answer both 'why was this allowed?' and 'what did this flawed intent let happen?'
Mapping to the Governance Frameworks
A serious deployment does not govern in a vacuum; it must answer to frameworks, and the intent ledger is what lets it do so with evidence rather than narrative. The NIST AI Risk Management Framework organizes AI governance into functions — broadly, governing (establishing the structures and accountability), mapping (understanding context and intended use), measuring (assessing behavior against criteria), and managing (acting on what is found). Intent-based governance instantiates each: declaring and signing intents is mapping intended use per task; the enforcement decisions are managing risk in the moment; conformance measurement is measuring against defined criteria; and the ledger and its accountability structure are the governing function made concrete.
The regulatory frameworks demand specific artifacts, and the ledger supplies them. The EU AI Act requires, for high-risk systems, technical documentation of intended purpose and record-keeping sufficient to trace a system's functioning; the versioned intents are the per-task statement of intended purpose, and the audit trail is the traceability. ISO/IEC 42001, as a management-system standard, expects an organization to define objectives and controls for its AI and to demonstrate they are operating; the ledger of intents, decisions, and conformance results is that demonstration, kept as living evidence rather than a one-time attestation. The mapping is not cosmetic — each framework asks for something the ledger, by construction, already contains.
The value of making the mapping explicit is that it converts compliance from a parallel, duplicated effort into a byproduct of governing well. A team that governs by intent and keeps a complete ledger is not doing governance and then separately assembling compliance evidence; the evidence is the governance record, indexed to the frameworks' requirements. This is the practical payoff of the whole model at scale: the same artifacts that let the team run their fleet safely are the artifacts that demonstrate, to an auditor or a regulator, that they are running it safely.
| Framework element | Intent-governance artifact | Evidence it provides |
|---|---|---|
| NIST AI RMF — Map | Declared, signed intents | Intended use, per task |
| NIST AI RMF — Measure | Conformance results | Behavior vs. defined criteria |
| EU AI Act — record-keeping | Continuous audit trail | Traceability of functioning |
| ISO/IEC 42001 — controls | The intent ledger | Living evidence controls operate |
Governing the Governance
A fleet's intents are themselves a population that needs governing, which introduces a meta-level the model has to address. Intents are declared by many parties, evolve through versions, and can drift as a population — accumulating inconsistencies, overlapping in conflicting ways, or aging into standards that no longer match the tasks they govern. Just as least-privilege drift afflicts a fleet's permissions, intent drift afflicts a fleet's declared purposes, and the ledger is the instrument that makes it visible: because every intent is recorded with its version and provenance, the population can be inspected for conflicts, staleness, and unauthorized declarations.
The controls at this level parallel the ones for any governed population. Provenance answers who may declare an intent, so the set of governing standards cannot be expanded by an unauthorized party. Versioning with an append-only history makes every change to an intent accountable and reversible in the record. And periodic review against the ledger surfaces the intents that have drifted — those whose conformance is chronically poor, those that conflict with others, those governing tasks that no longer exist. Without this meta-governance, an intent system decays exactly as an unmanaged permission system does, accumulating cruft that erodes the guarantees the whole model was meant to provide.
This closes the model on itself. Intent-based governance authorizes an agent's actions by declared purpose; governing the governance authorizes and maintains the declared purposes themselves. The ledger serves both — it is the runtime evidence that actions were governed and the management evidence that the governing standards are themselves sound, current, and authorized. A fleet whose intents are captured, enforced, measured, recorded, and periodically re-examined against their own record has an intent-governance system that is not merely present but demonstrably maintained, which is the standard scale and regulation both ultimately demand.
Limitations and Threats to Validity
This article describes a scaling architecture and its mapping to frameworks, not a certified compliance solution, and the caveats are important. Mapping intent-governance artifacts onto framework requirements is an argument that the artifacts supply what the frameworks ask for, not a substitute for the formal conformity assessment those frameworks may require; a ledger that contains the right evidence still has to be assessed against the specific, evolving legal and standards text by qualified parties, and nothing here should be read as legal advice or as a guarantee of compliance. The frameworks cited are living documents, and a mapping accurate today must be maintained as they change.
The architecture's guarantees are also only as strong as the ledger's completeness and integrity. An audit trail with a gap cannot explain the outcomes on either side of the gap, and an append-only record that is not actually append-only — that can be quietly edited by a privileged party — provides the appearance of trustworthy testimony without the substance, which is worse than no record because it invites misplaced confidence. The ledger's own security, therefore, becomes part of the trust base: its integrity controls are as important as the governance content it holds. The honest conclusion is that at scale the intent ledger is the governance made durable — it turns per-action checks into standing, queryable, auditable evidence — and its worth is exactly its completeness, its integrity, and the fidelity of its mapping to the obligations a given deployment must actually meet.
Key takeaways
- Governing a fleet is a change in kind: fleet-level questions — which intents are active, which share a constraint, which are degrading — require intents and their outcomes to be recorded, related, and queryable, not evaluated and forgotten.
- The intent ledger is an append-only record binding each intent to its provenance and version and to the decisions and conformance results under it; append-only is essential because an editable governance record can be made to lie.
- The audit trail is the continuous chain from provenance to intent version to decision to action, traceable backward (why was this allowed?) and forward (what did this flawed intent let happen?).
- The ledger maps directly onto frameworks: declared intents are NIST AI RMF mapping and EU AI Act intended-purpose documentation, conformance results are RMF measurement, and the trail is the Act's required record-keeping.
- This makes compliance a byproduct of governing well — the same artifacts that run the fleet safely are the evidence that demonstrates it, rather than a separate, duplicated effort.
- Intents are themselves a population to govern: provenance authorizes who may declare them, versioning makes changes accountable, and periodic review against the ledger surfaces intent drift before it erodes the model.
Practitioner Toolkit
Copy-paste, strictly defensive artifacts you can use today. Nothing here attacks a real system.
Confirm the fleet's intents are a trustworthy, queryable, auditable system of record.
- Every declared intent is written to an append-only ledger with its provenance and version — no intent governs without a durable record.
- The ledger relates each intent to the decisions it drove and the conformance results measured against it, so fleet-level questions are queries, not reconstructions.
- A continuous audit trail links every action to its decision, rule, intent version, and provenance, traceable both backward and forward.
- The ledger's append-only integrity is enforced and monitored — a record that can be edited provides false confidence.
- Intent-governance artifacts are indexed to the frameworks the deployment must answer to (NIST AI RMF, EU AI Act, ISO/IEC 42001).
- Intents are periodically reviewed against the ledger for drift — conflicts, staleness, and unauthorized declarations — and provenance limits who may declare them.
An append-only record binding an intent to its governance outcomes.
ledger_entry:
intent_id: inv-reconcile-2026-03
version: 3
provenance: { declared_by: reconciliation-service, signed: true }
decisions: [ {action: read, verdict: allow}, {action: email, verdict: deny} ]
conformance: { completeness: 0.98, off_intent_fraction: 0.00 }
coverage: [ resources, actions ] # dimensions measured
append_only: true # correction = new entry
trace: { back: action->decision->rule->version->provenance }The smallest path from per-agent checks to fleet-wide, auditable evidence.
- Write every declared intent, with provenance and version, to an append-only ledger the moment it governs anything.
- Record each governance decision and conformance result against its intent, so the record answers fleet-level questions directly.
- Keep a continuous audit trail from action back to provenance, and confirm no link is ever taken on faith.
- Index the ledger to your applicable frameworks and schedule a periodic review of the intent population for drift.
Glossary
- Intent ledger
- An append-only record binding every declared intent to its provenance and version and to the governance decisions and conformance results measured under it.
- Append-only
- The property that ledger entries are added and never altered, so a correction is a new entry, preserving the true history of governance.
- Audit trail
- The continuous causal chain linking an action to the decision, rule, intent version, and provenance that justified it, traceable in both directions.
- Intent drift
- The degradation of a fleet's declared intents as a population — accumulating conflicts, staleness, or unauthorized declarations — analogous to least-privilege drift.
- NIST AI RMF functions
- The organizing functions of the NIST AI Risk Management Framework — govern, map, measure, and manage — that intent governance instantiates per task.
- Record-keeping (EU AI Act)
- The Act's obligation that high-risk AI systems maintain logs sufficient to trace their functioning, met by a continuous audit trail.
- Management system (ISO/IEC 42001)
- A standard expecting an organization to define AI objectives and controls and demonstrate they operate, evidenced by the living intent ledger.
- Governing the governance
- The meta-level of authorizing, versioning, and reviewing the declared intents themselves, so the governing standards stay sound, current, and authorized.
References
- NIST AI 100-1, AI Risk Management Framework (AI RMF 1.0)
- NIST AI 600-1, Generative AI Profile (2024)
- Regulation (EU) 2024/1689, the EU Artificial Intelligence Act (2024)
- ISO/IEC 42001:2023, AI Management System (AIMS)
- NIST SP 800-207, Zero Trust Architecture (2020)
- OWASP Agentic Security Initiative, Agentic AI Threats and Mitigations (2025)
- OWASP Top 10 for LLM Applications (2025)
- MITRE ATLAS (Adversarial Threat Landscape for AI Systems)