FideAI

FID-077 · Open question

Independent Agent Incident Investigation and Evidence Sufficiency

What operational evidence lets independent investigators reconstruct an agent incident, distinguish competing explanations, and identify which interventions could have changed the outcome?

Why the question remains open

Logs may show an outcome without establishing its cause. Independent investigation needs an evidence standard that supports scrutiny while limiting exposure of private information and acknowledging what missing records leave unknown.

Working hypothesis

A proposition to test, not a finding.

Structured, integrity-protected action and permission records will improve reconstruction accuracy over ordinary logs. Additional records may yield diminishing benefits or misleading confidence, and neither condition establishes access to a model's private reasoning.

Proposed method

How the question could be tested

  • 01Generate known-cause incidents in isolated synthetic workflows, including delegation failures, unauthorized actions, and benign look-alikes.
  • 02Give blinded investigators different evidence bundles: outcome-only, ordinary logs, and structured tool, permission, source, intervention, and delegation records.
  • 03Score reconstruction against ground truth, calibration of uncertainty, false attribution, reviewer agreement, and time. Remove or alter records to test sensitivity; replay candidate interventions where valid.

Needed controls

What must constrain the study

  • 01Use synthetic cases initially; require consent, access agreements, and independent disclosure review before any real incident study.
  • 02Separate observed actions, inferred explanations, and unknowns. Record custody, redaction, missingness, and alternative causal accounts.
  • 03Do not require private chain-of-thought or indiscriminate employee surveillance. Evaluate evidence minimization and confidentiality alongside investigative utility.

Relationship to existing work

Operationalizes the evidence questions in FID-074 and complements FID-071 on confidential memory. FID-024 remains a separate faith-domain incident database proposal.

Expected outputs

Artifacts the work should produce

  • 01A minimum-evidence schema and investigator reporting template.
  • 02A synthetic incident corpus, evidence-ablation study, and reproducibility guidance.

Open questions

Uncertainties the protocol must resolve

  • 01When does redaction prevent meaningful independent review?
  • 02Which causal claims remain unsupported even with complete action logs?

Open question

Open work

Primary need: incident response, trace analysis, data provenance, privacy, independent review

  • Incident responders and independent researchers to reconstruct blinded cases.
  • Privacy and provenance specialists to review evidence handling.