> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate an Agent Conformity Dossier

> Export a versioned, downloadable evidence pack for one AI agent — model card, disclosure settings, evaluation results, fairness cohorts, oversight records, and audit-log aggregates — in either the EU AI Act or the AIUC-1 profile.

# Generate an Agent Conformity Dossier

One endpoint stitches the compliance and security evidence your account
already produces — disclosure settings, eval runs, tool-approval records,
decision audit logs — into a single export for one agent. Request it as JSON
for machine processing, or as a download-ready HTML pack to attach to a
regulatory filing or an enterprise security review.

The endpoint paths below are relative. Send them against
`https://api.orbit.devotel.io/api/v1`.

## Prerequisites

* An agent with a saved, versioned configuration — the dossier reports the
  agent's current row, including its `version` counter.
* An API key whose user holds the **owner**, **admin**, or **developer**
  role (read). Every export is written to the account's audit log.
* Evidence to report on. Sections read the records you have already
  produced: disclosure settings, eval runs, tool-approval gates, and audit
  events generate their sections. A section with no backing records still
  renders — it is marked `unavailable` instead of failing the export.

## Choose a profile

The same endpoint compiles two profiles; `profile=` selects which one.
Both share the model card and the human-oversight evidence; everything
else is profile-specific.

| Profile | Cited framework | Sections |
| - | - | - |
| `eu_ai_act` (default) | EU AI Act articles | Model card, AI-disclosure configuration (Art. 50), evaluation results (Art. 15), fairness and bias cohorts (Art. 10), built-in red-team coverage (Art. 15), human oversight (Art. 14), decision audit aggregates (Art. 12 / Art. 22 §3) |
| `aiuc1` | CSA AIUC-1 control families | Model card, agent identity (signing keys, discovery mode), access control (tool allowlist, approval gates), transport security, message integrity, runtime containment — plus a crosswalk mapping its families to OWASP Agentic ASI03, CSA AI Controls Matrix, CSA MAESTRO, and NIST AI RMF |

Pick `eu_ai_act` when the export feeds a European regulatory or Annex IV
conformity review. Pick `aiuc1` when a security team is evaluating the
agent against agentic-AI control frameworks — the crosswalk answers the
framework-to-control mapping such reviews cite without a second pass.

## Call the endpoint

The endpoint defaults to `format=json` and `profile=eu_ai_act`; both
query parameters are optional. JSON returns the structured dossier
object:

```bash theme={null}
curl -s "https://api.orbit.devotel.io/api/v1/agents/agent_abc123/conformity-dossier?profile=eu_ai_act" \
  -H "X-API-Key: dv_live_sk_..."
```

HTML returns a styled, self-contained attachment. Save it under the
filename the server also suggests:

```bash theme={null}
curl -s "https://api.orbit.devotel.io/api/v1/agents/agent_abc123/conformity-dossier?profile=eu_ai_act&format=html" \
  -H "X-API-Key: dv_live_sk_..." \
  -o eu-ai-act-conformity-dossier-2026-09-29.html
```

For the AIUC-1 profile, pass `profile=aiuc1`; the suggested filename
changes to `aiuc1-agent-security-posture-<agent>-<date>.html`. A unknown
agent id returns `404`, and the endpoint is rate-limited to 30 requests
per minute — treat it as a serve-on-demand export, not a polling feed.

The JSON response carries a `readiness` block alongside the sections:

```json theme={null}
{
  "dossier": {
    "dossier_version": "1",
    "generated_at": "2026-09-29T07:00:00.000Z",
    "readiness": { "sections_present": 7, "sections_total": 7 },
    "sections": [ ... ]
  }
}
```

`readiness` compares the number of fully gathered sections against the
profile's total, so a downstream check can confirm the pack is complete
before it goes into a filing.

## Read the report

Three rendering rules hold for every section, in both formats:

* **No secrets, no keys.** Sections render configuration and counts — the
  prompt length in characters, tool and knowledge-base counts, eval
  pass/fail tallies, approval-status totals — but never prompt bodies,
  API keys, or signing-key material. The export is safe to hand to an
  external reviewer as-is.
* **Failures degrade per section, not per export.** A read that fails —
  or whose backing table is not provisioned on a legacy account — marks
  that one section `unavailable`. The remaining sections still gather,
  and the export succeeds; check `readiness.sections_present` for the
  count.
* **Assert evidence, not compliance.** The report documents what the
  platform can evidence for your configured posture; it makes no legal
  determination about your deployment.

The HTML pack is deterministic — the same state renders the same
document — so attach it with the generated date in its name and keep one
export per review cycle in your records.

## Dashboard equivalent

No curl required: open the agent in the dashboard, choose the
**Conformity dossier** tab, and pick the profile from the toggle at the
top of the tab. The tab renders the same dossier inline — per-section
status, the fairness cohort breakdown where present, the AIUC-1
framework crosswalk where present — and offers a download button that
exports the same JSON the endpoint serves. The disclaimer the API
includes is also shown in the tab, keeping the tenant-owned posture
framing next to the evidence.

## Troubleshooting

| Symptom | Fix |
| - | - |
| `404 NOT_FOUND` | The agent id does not exist in your tenant, or was deleted. Confirm the id from `GET /agents`. |
| `403` | The endpoint requires the **owner**, **admin**, or **developer** role. Mint the key for a user in one of those roles. |
| Section shows `unavailable` | The section's backing records were never provisioned or have no data yet — run an eval, enable disclosure, or route tool calls through the approval gate, then re-export. The rest of the dossier still exported; it never fails as a whole. |
| `readiness.sections_present` \< `sections_total` | One or more sections degraded. Re-run after covering the missing evidence, or accept the partial pack consciously before filing it. |
| HTML downloaded with no styling | The HTML pack is self-contained. If your pipeline rewrites attachments, make sure it does not strip the inline `<style>` block. |

## Tenant-owned posture

Per the [compliance guide](/compliance/eu-ai-act): the dossier documents
what the platform can evidence about the posture **you** configured —
your disclosure texts, your eval results, your approval-gate records,
your audit aggregates. Orbit compiles the evidence; the judgment that
your deployment satisfies a regulation stays with you, and the
disclaimer in every export says so in writing. That boundary is
deliberate: a vendor asserting compliance on your behalf would be a
liability, not a feature.

## See also

* [EU AI Act posture guide](/compliance/eu-ai-act) — the articles the default profile cites.
* [Adversarial red-team testing](/agents/red-team) — generate the robustness evidence the dossier cites.
* [Guardrail analytics tuning](/guides/guardrail-analytics-tuning) — tune the policies the access-control sections describe.
* [Safely Roll Out an AI Agent](/guides/ai-agent-rollout-pipeline) — the pipeline that produces the evaluation and fairness evidence this export packages.
