Generate an Agent Conformity Dossier
One endpoint stitches the compliance and security evidence your account already produces — disclosure settings, eval runs, tool-approval records, decision audit logs — into a single export for one agent. Request it as JSON for machine processing, or as a download-ready HTML pack to attach to a regulatory filing or an enterprise security review. The endpoint paths below are relative. Send them againsthttps://api.orbit.devotel.io/api/v1.
Prerequisites
- An agent with a saved, versioned configuration — the dossier reports the
agent’s current row, including its
versioncounter. - An API key whose user holds the owner, admin, or developer role (read). Every export is written to the account’s audit log.
- Evidence to report on. Sections read the records you have already
produced: disclosure settings, eval runs, tool-approval gates, and audit
events generate their sections. A section with no backing records still
renders — it is marked
unavailableinstead of failing the export.
Choose a profile
The same endpoint compiles two profiles;profile= selects which one.
Both share the model card and the human-oversight evidence; everything
else is profile-specific.
Pick
eu_ai_act when the export feeds a European regulatory or Annex IV
conformity review. Pick aiuc1 when a security team is evaluating the
agent against agentic-AI control frameworks — the crosswalk answers the
framework-to-control mapping such reviews cite without a second pass.
Call the endpoint
The endpoint defaults toformat=json and profile=eu_ai_act; both
query parameters are optional. JSON returns the structured dossier
object:
profile=aiuc1; the suggested filename
changes to aiuc1-agent-security-posture-<agent>-<date>.html. A unknown
agent id returns 404, and the endpoint is rate-limited to 30 requests
per minute — treat it as a serve-on-demand export, not a polling feed.
The JSON response carries a readiness block alongside the sections:
readiness compares the number of fully gathered sections against the
profile’s total, so a downstream check can confirm the pack is complete
before it goes into a filing.
Read the report
Three rendering rules hold for every section, in both formats:- No secrets, no keys. Sections render configuration and counts — the prompt length in characters, tool and knowledge-base counts, eval pass/fail tallies, approval-status totals — but never prompt bodies, API keys, or signing-key material. The export is safe to hand to an external reviewer as-is.
- Failures degrade per section, not per export. A read that fails —
or whose backing table is not provisioned on a legacy account — marks
that one section
unavailable. The remaining sections still gather, and the export succeeds; checkreadiness.sections_presentfor the count. - Assert evidence, not compliance. The report documents what the platform can evidence for your configured posture; it makes no legal determination about your deployment.
Dashboard equivalent
No curl required: open the agent in the dashboard, choose the Conformity dossier tab, and pick the profile from the toggle at the top of the tab. The tab renders the same dossier inline — per-section status, the fairness cohort breakdown where present, the AIUC-1 framework crosswalk where present — and offers a download button that exports the same JSON the endpoint serves. The disclaimer the API includes is also shown in the tab, keeping the tenant-owned posture framing next to the evidence.Troubleshooting
Tenant-owned posture
Per the compliance guide: the dossier documents what the platform can evidence about the posture you configured — your disclosure texts, your eval results, your approval-gate records, your audit aggregates. Orbit compiles the evidence; the judgment that your deployment satisfies a regulation stays with you, and the disclaimer in every export says so in writing. That boundary is deliberate: a vendor asserting compliance on your behalf would be a liability, not a feature.See also
- EU AI Act posture guide — the articles the default profile cites.
- Adversarial red-team testing — generate the robustness evidence the dossier cites.
- Guardrail analytics tuning — tune the policies the access-control sections describe.
- Safely Roll Out an AI Agent — the pipeline that produces the evaluation and fairness evidence this export packages.