What does SOC 2 require for AI agents?
SOC 2 auditors increasingly ask for evidence that AI agents with data access are governed the same way human employees are. Centurian generates SOC 2-ready evidence (access logs, attestation, audit trail) per agent, automatically.
Agents are already inside SOC 2’s scope
SOC 2's Trust Services Criteria cover access control, change management, and monitoring for anything that touches customer data. That scope was written for human employees and service accounts, but the criteria don't actually say "human", they say "any principal with access." An AI agent holding a database connection or an API key is the exact access-control surface a SOC 2 audit already covers. Auditors asking about agents specifically is the framework catching up to reality, not a new requirement being invented.
In practice, that means an auditor will ask the same three questions about an agent that they ask about a new hire: who authorized this access, what can it actually do, and can you show me what it did. Most companies can answer the first two. Almost none can answer the third for an AI agent today. See the audit trail page for how that evidence gets built.
Why the evidence should come from outside
57% of organizations prefer third-party-built compliance and governance tooling over internally built (KPMG), an independence preference that predates AI agents but applies directly to them. The team that configured an agent's access is not the ideal sole source of the evidence that the access was appropriate; a SOC 2 auditor will trust an independent record more than a self-reported one.
Centurian generates three evidence primitives automatically: per-agent access logs (what data and systems each agent touched), attestation records (who owns the agent and what it's authorized to do), and the bitemporal, signed audit trail (every action, timestamped). Deloitte Zora AI, PwC Agent OS, and KPMG Workbench build comparable layers internally at large enterprises as part of consulting engagements; Centurian ships the same primitives as a self-serve product for teams that don't have a consulting budget for it. See proving AI agent compliance for how this rolls into a full compliance package.
FAQ
First agent free, forever · No credit card