AuditBadger launches auditable agentic compliance: AI agents propose, humans approve, and the audit trail proves it

AuditBadger launches auditable agentic compliance: AI agents propose, humans approve, and the audit trail proves it
Diagram of AuditBadger’s approval gate: an AI agent produces a change set, a human reviews and approves it, and only then is it applied and recorded in the audit trail. No direct write path exists.
AuditBadger has opened its full compliance workflow to AI agents, with a constraint: agents cannot change anything. Every change an agent proposes must be explicitly approved by a person before it is applied, and the audit trail names both the agent and the approver. The company calls the category auditable agentic compliance. It is not the first compliance platform to connect AI agents, and says so. It believes it is the first where the approval gate cannot be turned off.

POZNAƃ, POLAND – September 1, 2026 – AuditBadger today released agent access to its full compliance workflow, letting AI agents such as Claude, ChatGPT and Codex do real SOC 2 and ISO 27001 work inside a customer’s account. Every change an agent proposes requires explicit human approval before it is applied, and every applied change is recorded in the audit trail with the agent named as the actor and the approving person named alongside it.

AuditBadger is calling the category auditable agentic compliance: agent-native, human-gated GRC.

The company is making a deliberately narrow claim. AuditBadger is not the first compliance platform to offer an MCP server, and says so plainly. It believes it is the first where an external AI agent can work across the compliance workflow under a mandatory human approval gate that cannot be disabled, with the agent attributed as a distinct actor in a retained audit trail.

The problem: agents that write directly create audit findings

Compliance automation vendors have spent the past year connecting AI agents to customer data. Most of those integrations let an agent write directly once it is authorised, with the change recorded against the human’s API credential.

That creates a problem auditors are already flagging. SOC 2 expects privileged actions to be attributable to an accountable individual, not to a service account or an autonomous agent. ISO 27001’s logging requirements point the same way. The EU’s AI Act adds record-keeping and human oversight obligations for automated systems operating inside processes a person remains accountable for.

“If an agent writes straight into your control set, you have just created a change with no request, no approval and nobody accountable, sitting in the same evidence pile your auditor is about to sample,” said Maciej Litwiniuk, founder of AuditBadger. “You have automated your way into a finding. When the auditor asks who approved this, ‘the AI did it’ does not close the question. It opens one.”

How it works

Agents connect through a dedicated endpoint using scoped tokens rather than admin API keys. Each token carries per-module permissions, and an agent sees exactly what the authorising user sees, not more.

Agents can read projects, controls, documents and evidence, and can propose changes across the compliance workflow. They cannot apply them. Each proposed change becomes a change set that a person reviews and approves, after which a separate step performs the change. Filtering the audit log by the agent actor channel reconstructs every change an agent ever caused, the proposal it came from, and who approved it. The approval record is stored separately from conversation content, so clearing chat history does not clear the evidence.

The gate is architectural rather than configurable. There is no setting that restores direct agent writes, and the company’s test suite fails the build if one is introduced.

Operational controls include two independent pause switches (one stopping new agent traffic, one stopping approved work from being applied), expiring proposals, four layers of rate limiting on the agent endpoint, and strict content handling on agent uploads: a narrow file allowlist, outright refusal of PDFs carrying active content, and image re-encoding with metadata stripped.

AuditBadger is explicit that uploads are not virus-scanned and are recorded as such.

Built by someone who sat on the other side of it

AuditBadger achieved SOC 2 Type II certification using only its own platform, with no external consultants, across an observation window running March 27 to June 27, 2026.

“We built the gate before we built the agent, and in that order on purpose,” said Litwiniuk. “Going through our own Type II is what convinced me that this had to be proposals. I did not want to be the person explaining to an auditor why a model edited a policy at two in the morning.”

He added: “If someone shipped this architecture before we did, I would like to know, and we will correct our own page. I would rather be second and accurate than first and wrong.”

Availability and pricing

Auditable agentic compliance is available today to all AuditBadger accounts at no additional cost. AuditBadger costs $250 per month flat, with no per-user fees and no usage limits, and there is no separate charge per agent.

Existing MCP users must migrate: the legacy endpoint is removed in this release and replaced by a new agent endpoint requiring a new token type. Migration instructions are in the product documentation.

About AuditBadger

AuditBadger is a compliance platform for small and mid-sized teams that need SOC 2 or ISO 27001 without a compliance department, consultants, or enterprise pricing. It supports SOC 2 and ISO 27001 in both the 2013 and 2022 editions, with over 120 automated evidence checks across 12 integrations running monthly, some weekly, plus on demand. The platform is available in English, Polish, German, Spanish and Dutch, and costs $250 per month flat. AuditBadger was certified SOC 2 Type II using only AuditBadger, with zero external consultants.

Founded by Maciej Litwiniuk after a brutal ISO 27001 certification in 2019 at his previous software company, AuditBadger is the tool he wished he had.

Media Contact
Company Name: AuditBadger
Contact Person: Maciej Litwiniuk
Email: Send Email
Address:Emilii Sczanieckiej 9a/9
City: Poznan
State: Wielkopolska
Country: Poland
Website: https://auditbadger.com