The business record that will decide a contested AI-assisted decision is not the prompt. It is the resolution: proof of what was solved, who is accountable for solving it, and whether the claimed outcome actually held. That record does not exist inside most organizations today, and building it is harder than it looks.
Desh Urs, founder of iBridge and a specialist in legal and compliance data governance, made a sharp case for the first part of that idea this month. His piece, “Every Prompt Is a Decision You’re Not Auditing,” argues that the prompt is a business record: the modern equivalent of the memo, the meeting note, the marked up draft. Organizations that treat AI policy as inventory rather than governance, he warns, will relearn the lesson email taught them twenty years ago. He is right, and the prompt is exactly where the record starts. The record that ultimately settles a dispute sits one layer further downstream, in the resolution the prompt fed into.
The Two Questions After Approval
Urs puts four questions to leadership teams: who created the prompt, what information was supplied, how was the output reviewed, and who approved the final decision. Those four questions get an organization to the moment of approval, which is the hardest part of the chain to reconstruct after the fact, and the part most organizations have no record of at all today. Two more questions sit downstream of his four: did the approved action get executed as recommended, and can the organization prove the outcome it claims actually occurred.
A contract clause negotiated from an AI assisted draft, an insurance claim adjusted on an agent’s recommendation, a hiring decision informed by a model’s output. In each of these, the exposure is not that AI touched the work. It is that the chain of proof runs out somewhere between the model’s output and the verified result, past the point Urs’s four questions cover.
Atomic Resolution Was Built for This Chain
This is the structural problem Resolution as a Service (RaaS) was designed around. CPAG defines an Atomic Resolution as the discrete, verifiable unit of AI assisted work, and it must satisfy three conditions to be defensible.
- Verifiable: the problem was solved, not merely attempted.
- Attributable: the resolution traces directly to the platform’s AI execution, not to an unrecoverable black box.
- Finite: the resolution has a defined endpoint, so accountability does not extend into an open ended agentic loop.
A prompt satisfies none of these on its own. It documents what was asked. It does not document what was resolved, who is accountable for the resolution, or where the resolution ended.
Why Nobody Has Actually Solved the Audit Layer Yet
The obstacle here is not technical. It is who is allowed to hold the record.
A SaaS vendor building this audit layer into its own product and calling the problem solved runs into a plain conflict of interest. A vendor that owns the record of its own agent’s work is grading its own homework. When a dispute gets resolved in the vendor’s favor, using a record the vendor itself controls, the customer has every reason to question it. The audit layer that eventually settles these disputes will need to sit outside the vendor whose agent did the work, the way a notary is not a party to the contract it witnesses.
That conflict is real today, but it is dormant. Nobody is pricing it in because nobody has been burned by it yet. What changes that is a specific, recognizable event: a contested AI-assisted decision, a denied claim, an overridden contract term, a disputed hiring call, that draws real attention, where the only record is one the vendor controls, and that record does not hold up under scrutiny. A dispute like that would do for the audit trail question what the SaaSpocalypse did for seat pricing: move it from a structural argument to a recognized problem.
Consider a mid market insurance SaaS vendor whose claims adjustment AI agent recommends a denial. The prompt log shows what the agent was asked. It does not show whether a human reviewed the recommendation, whether the denial was issued as recommended, or whether the outcome matched what the agent predicted. That gap is a smaller version of a large, documented problem. CPAG’s Biological Middleware Tax figure puts the conservative, near term automatable cost of knowledge workers acting as manual data transfer cables between systems that will not interoperate at $600 billion a year. It sits inside a wider 2.4 trillion dollar Friction Economy: $1.4 trillion in legacy system maintenance, $600 billion in biological middleware labor friction, and $400 billion in supply chain documentation friction. Every one of those dollars is, in part, someone manually reconstructing proof that a system was never built to produce on its own, which is exactly the job an independent resolution record would remove.
“The organizations that can prove their AI assisted decisions will deploy AI faster, not slower, because proof is what lets leadership stop reviewing everything by hand.”
Why Urs’s Own Client List Makes the Case
Urs’s practice runs through legal discovery, county government records, and compliance data. That is not incidental to his argument. Regulated industries will be one of the first markets to adopt RaaS precisely because their standard operating procedures are already written down, which makes an Atomic Resolution structurally easier to define than in an unregulated environment. The record Urs is describing does not need a new governance program bolted onto an existing security stack. It needs an architecture where the resolution, not the prompt, is the record, and where the party holding that record is not the same party with an incentive to shade it.
Whether a complete record is the same thing as accountability, or whether accountability still requires a human who can be asked to explain the record in a room even when the record is airtight, is the harder question underneath this one.
Prescription
Pick one decision class your organization already lets AI touch: claims, contract review, hiring, collections. Map it end to end, from the evidence the model received, to its recommendation, to the human review, to the action actually taken, to the verified outcome. At each step, ask a second question: who currently holds the proof. If the answer is always “we do,” that is the exposure, independent of whether the AI performed well.
The Socratic question for your leadership team: if a regulator asked you to prove not what your AI was asked, but what it resolved, and asked who is vouching for that proof besides you, what would you say?