
One Ledger, Four Readers: Scoping Disclosure to Each Audience
A complete AI record raises a fair objection: not everyone should see everything. The answer is scoped disclosure — one tamper-evident ledger, four different views, each showing a reader exactly what they're entitled to and no more.
- Katya SavenkovaDirector of Operations
In this article
The instinctive worry about recording everything an AI does is over-disclosure: surely the auditor, the regulator, the user, and your own engineer shouldn't all see the same thing. They shouldn't, and they don't have to. One record can serve four readers, because completeness and disclosure are separate decisions — the ledger is complete; what each reader sees is scoped.
Completeness and disclosure are not the same
These two ideas get conflated, and the confusion drives bad choices — teams under-record to avoid over-disclosing, and end up unable to answer anything. The record should be complete, because you can't disclose what you never captured. What each audience sees is a separate control layered on top. Keep everything; show each reader their slice.
The four readers
- The user sees their own interactions and what was decided about them — the basis for exercising their rights.
- The regulator sees the evidence relevant to the specific decision or complaint under review, not the whole system.
- The auditor sees that controls fired and obligations were met, often without needing the raw content behind them.
- The engineer sees the operational detail needed to debug and improve, within policy.
Four questions, four scopes, one source of truth underneath them all.
Why one source matters
The alternative to scoped views over one record is separate records per audience — a user-facing log, an auditor's report, an engineer's trace — which immediately diverge and quietly contradict each other. Then a discrepancy between two views becomes its own problem. Scoping views over a single tamper-evident ledger means every reader is looking at projections of the same underlying truth, so they can differ in detail but never in substance.
Don't keep four records that disagree. Keep one record and show four scoped views of it — so disclosure is controlled without truth being fragmented.
The guarantee holds for everyone
Scoping changes what a reader sees, not whether it's trustworthy. The integrity guarantee — that the record is complete and unaltered — holds regardless of which view you're granted. A regulator's narrow slice is exactly as tamper-evident as the engineer's detailed one, because they're both drawn from the same signed chain. Access is scoped; verifiability is universal.
Disclosure as policy, not access control theater
Scoped disclosure is governed by policy you set, and — like other controls — the fact of a disclosure and its scope can themselves be recorded. So 'who saw what, and why' is answerable too. This is what turns need-to-know from a slogan into a mechanism: the record is whole, the views are principled, and even the act of disclosing is on the record.
Frequently asked questions
One truth, four principled views. See how scoped disclosure lets a user, regulator, auditor, and engineer each see exactly what they're entitled to — over one tamper-evident record. Book a walkthrough.
Part of