Agentic Workflow Forensics Field Definition v1.1

Govern the workflow before action. Reconstruct it after action. Repair it after failure.

Agentic Workflow Forensics is the field of analyzing AI-agent workflows as reconstructable behavioral trajectories. It examines how an AI system, agent, assistant, model-mediated toolchain, or human-agent workflow moves from instruction to action, output, downstream reliance, evidence, and recovery.

The field asks a stricter question than whether an agent produced a plausible answer or completed a task:

Can the workflow’s objective, scope, state, verification, stop conditions, evidence, handoffs, and recovery path be reconstructed from preserved evidence?

If a material claim cannot be established, the method preserves that uncertainty and states its consequence. It does not fill an evidence gap with an aggregate score, a maturity label, or an inference about hidden model intent.

What is the reconstructability gap?

The reconstructability gap is the distance between what happened in an AI-mediated workflow and what can be proven afterward. It appears when prompts, tool calls, source versions, verification results, approvals, reliance paths, or recovery actions are missing or ambiguous.

An organization may know that an incident occurred while remaining unable to establish:

Agentic Workflow Forensics treats reconstructability as a design property before an incident and an evidentiary question after one.

What are the eight control surfaces?

The field uses eight Agentic Workflow Control Surfaces as modular units of analysis:

Control surface Material question
Objective What was the agent supposed to do?
Scope What could the agent touch, say, change, advise, or commit?
State / Source of Truth What authoritative state governed the action?
Verification What proved the task, claim, or action was valid?
Stop Condition When did the workflow have to suspend, escalate, or refuse?
Evidence What records remain to establish what happened?
Handoff / Reliance Who or what received and relied on the output?
Recovery How could error or harm be reversed, corrected, or repaired?

Attribution is not a ninth surface. It is a claim-level boundary applied across all eight surfaces.

How is workflow failure different from output failure?

An output failure is an incorrect, fabricated, harmful, incomplete, or misleading result. A workflow failure occurs when the surrounding process cannot prevent, detect, reconstruct, contain, or recover from that output or action.

Output-level description Workflow-forensic description
The chatbot hallucinated a policy. The answer was not bound to an authoritative policy source, verified before reliance, or escalated under ambiguity.
The coding agent said it was done. Completion was accepted without task-relevant evidence, allowing false-green completion.
The legal assistant fabricated citations. Generated state entered an institutional record without authentication, a stop condition, or a governed handoff.
The infrastructure agent deleted data. Scope, verification, evidence, stop, and recovery surfaces failed around destructive capability.

The model error still matters. Agentic Workflow Forensics adds the operational path through which the error became consequential.

What are the preventive and reconstructive branches?

Continuity-Governed Prompting (CGP) is the preventive branch. It governs the next action by binding work to verified objective, scope, state, verification, stop, evidence, handoff, and recovery conditions.

The Agentic Reconstruction Method (ARM) is the reconstructive branch. It examines the last action and determines what evidence establishes, what remains unknown, where attribution breaks, and what recovery is required.

The Next-Prompt Protocol is a high-discipline implementation pattern for CGP. SCOPA is an open-source, local-first runtime that maps and enforces a bounded subset of workflow-control behavior. Neither is required for every application of the field.

Where does the field apply?

Agentic Workflow Forensics applies whenever AI output or action influences behavior, authority, commitment, evidence, system state, or real-world reliance. Relevant workflows include coding, infrastructure, customer support, legal drafting, health-adjacent support, research, education, HR, insurance, procurement, sales, compliance, and public services.

A system does not need to be fully autonomous. A human-agent workflow becomes relevant when AI-created state enters a decision, filing, deployment, customer commitment, institutional record, or user reliance path.

How does this differ from observability and AI governance?

Observability, provenance, incident response, red teaming, digital forensics, and AI governance each contribute important capabilities. Agentic Workflow Forensics translates their shared concerns into a workflow-level reconstruction discipline. See AI-Agent Observability vs. Workflow Reconstructability for a bounded comparison.

What can the current evidence support?

The field definition, eight-surface control model, public incident demonstration, audit templates, and open-source implementation work are available as methodology and operational artifacts. A prospective validation experiment is still in preparation. No confirmatory data have been collected, and no empirical validation claim is made here. See the current experiment status.

Canonical source and citation status

This page presents the public web edition of Agentic Workflow Forensics: Field Definition v1.1, dated August 5, 2026, by Dylan D. Mobley, The Heart AI Foundation. A DOI-bearing paper is in preparation. Until a frozen public paper identity exists, cite this versioned web page with its access date and do not describe the field or its determination instrument as empirically validated.

Agentic Workflow Forensics Experiment Status — Current public boundary for the prospective SCOPA reconstructability determination validation experiment: preparation continues, confirmatory execution is not authorized, and no confirmatory data have been collected.

AI-Agent Observability vs. Workflow Reconstructability — Observability shows signals from a running AI system; reconstructability determines whether preserved evidence can establish what happened, under what authority, with what reliance, and with what recovery.

Public AI Incident Control-Surface Demonstrations — A bounded demonstration of how Agentic Workflow Forensics analyzes public AI incidents across consumer policy, health-adjacent support, and legal evidence workflows.

The Eight Agentic Workflow Control Surfaces — Eight auditable surfaces for determining whether an AI-agent workflow can be governed before execution, reconstructed after execution, and repaired after failure.