Skip to main content

Generate an Agent Conformity Dossier

One endpoint stitches the compliance and security evidence your account already produces — disclosure settings, eval runs, tool-approval records, decision audit logs — into a single export for one agent. Request it as JSON for machine processing, or as a download-ready HTML pack to attach to a regulatory filing or an enterprise security review. The endpoint paths below are relative. Send them against https://api.orbit.devotel.io/api/v1.

Prerequisites

  • An agent with a saved, versioned configuration — the dossier reports the agent’s current row, including its version counter.
  • An API key whose user holds the owner, admin, or developer role (read). Every export is written to the account’s audit log.
  • Evidence to report on. Sections read the records you have already produced: disclosure settings, eval runs, tool-approval gates, and audit events generate their sections. A section with no backing records still renders — it is marked unavailable instead of failing the export.

Choose a profile

The same endpoint compiles two profiles; profile= selects which one. Both share the model card and the human-oversight evidence; everything else is profile-specific. Pick eu_ai_act when the export feeds a European regulatory or Annex IV conformity review. Pick aiuc1 when a security team is evaluating the agent against agentic-AI control frameworks — the crosswalk answers the framework-to-control mapping such reviews cite without a second pass.

Call the endpoint

The endpoint defaults to format=json and profile=eu_ai_act; both query parameters are optional. JSON returns the structured dossier object:
HTML returns a styled, self-contained attachment. Save it under the filename the server also suggests:
For the AIUC-1 profile, pass profile=aiuc1; the suggested filename changes to aiuc1-agent-security-posture-<agent>-<date>.html. A unknown agent id returns 404, and the endpoint is rate-limited to 30 requests per minute — treat it as a serve-on-demand export, not a polling feed. The JSON response carries a readiness block alongside the sections:
readiness compares the number of fully gathered sections against the profile’s total, so a downstream check can confirm the pack is complete before it goes into a filing.

Read the report

Three rendering rules hold for every section, in both formats:
  • No secrets, no keys. Sections render configuration and counts — the prompt length in characters, tool and knowledge-base counts, eval pass/fail tallies, approval-status totals — but never prompt bodies, API keys, or signing-key material. The export is safe to hand to an external reviewer as-is.
  • Failures degrade per section, not per export. A read that fails — or whose backing table is not provisioned on a legacy account — marks that one section unavailable. The remaining sections still gather, and the export succeeds; check readiness.sections_present for the count.
  • Assert evidence, not compliance. The report documents what the platform can evidence for your configured posture; it makes no legal determination about your deployment.
The HTML pack is deterministic — the same state renders the same document — so attach it with the generated date in its name and keep one export per review cycle in your records.

Dashboard equivalent

No curl required: open the agent in the dashboard, choose the Conformity dossier tab, and pick the profile from the toggle at the top of the tab. The tab renders the same dossier inline — per-section status, the fairness cohort breakdown where present, the AIUC-1 framework crosswalk where present — and offers a download button that exports the same JSON the endpoint serves. The disclaimer the API includes is also shown in the tab, keeping the tenant-owned posture framing next to the evidence.

Troubleshooting

Tenant-owned posture

Per the compliance guide: the dossier documents what the platform can evidence about the posture you configured — your disclosure texts, your eval results, your approval-gate records, your audit aggregates. Orbit compiles the evidence; the judgment that your deployment satisfies a regulation stays with you, and the disclaimer in every export says so in writing. That boundary is deliberate: a vendor asserting compliance on your behalf would be a liability, not a feature.

See also