HOW FORKIT WORKS

ONE ACTION.
MANY EVIDENCE SOURCES.

Forkit does not replace your traces, IAM, MCP gateway, cloud audit or ERP logs. It reconciles those sources around the business action you need to understand.

THE ACTION OBJECT

A business consequence is the unit of accountability.

An Action record can hold direct evidence, inferred links and explicit gaps at the same time.

ACTION {
  action_id
  business_object_id
  human / actor
  delegated_authority
  agent + version
  model + provider
  identity / credential
  tool / MCP / API
  target system + object
  approval / policy state
  source evidence refs
  result / business effect
  confidence
  status
}

EVIDENCE RECONCILIATION

Read-only sources in. Action record out.

TARGET ARCHITECTURE
Agent tracesIAM / EntraMCP / API logsCloud auditSAP / CRM / ITSMApprovals / tickets
→
01NORMALIZER

Map heterogeneous evidence into stable fields.

→
02CORRELATION

IDs, time, resource hashes and business-object keys.

→
03ACTION RECORD

Evidence graph + confidence + missing/conflicting links.

PRIVACY MODEL

Collect the minimum evidence required for the claim.

FOOTPRINT · LIVE

Local-first

Monitoring history and detailed local evidence stay on the device. Optional public contribution is separate, versioned and allowlisted.

  • no prompts/responses in aggregate
  • no raw commands
  • no full paths
  • no account identity
ENTERPRISE · TARGET

Read-only evidence ingestion

Enterprise reconstruction is designed around source references, normalized evidence and explicit provenance—not copying arbitrary content into a new central system.

  • read-only connectors first
  • source evidence references
  • confidence per link
  • gaps preserved

SEE IT

Use the live reconstruction prototype, then compare it with local Footprint.