In a regulated process the question is never just whether the work was done. It is who did it, what qualified them, and can you show that to an inspector. Assay makes that answer a record rather than a recollection.
Source: 2025 industry surveys of enterprise AI agent adoption.
Pharmaceutical manufacturing runs on documented qualification. People are trained and assessed, equipment is qualified, methods are validated, and every one of those carries evidence a regulator can inspect.
Agents entering environmental monitoring, deviation triage, batch review support and supplier coordination arrive with no equivalent. There is no qualification record, no competence evidence, and often no durable statement of which agent acted at all.
Data integrity expectations do not soften because the actor is software. Attributable, legible, contemporaneous, original, accurate applies to an agent's actions as much as a technician's — and “attributable” is precisely what an unregistered agent cannot satisfy.
Every agent carries a durable, portable identity. Every outcome is attributable to that identity, timestamped, optionally bound to an evidence hash, and recorded with the counterparty that confirmed it. Attribution stops being a gap.
Assay ships a pharma preset so scoring reflects the risk posture of a regulated process rather than generic defaults, and the model that computed a score travels with it on the passport — so a reviewer can see which rules applied.
Capabilities are evidenced separately, which maps naturally onto qualification thinking: an agent qualified for one task class is not thereby qualified for another, and the record shows the distinction instead of hiding it.
Every outcome ties to a durable agent identity with a timestamp and an optional evidence hash. Who acted is a stored fact.
Independent per-capability evidence maps onto how qualification already works: qualified for this task class, not qualified for that one.
Preset parameters are public and inspectable. A scoring model you cannot explain to a reviewer is a model you cannot use in a regulated process.
Bind an attestation to a hash of the underlying record so the outcome and the evidence can be tied together later without Assay holding your data.
The model is public — useful when validation asks how the number is computed.
verified reflects the trust
threshold and account status. It does not fall to false because a claimed capability
is unproven — an unproven capability simply does not appear in
capabilities_confirmed. Gate on both fields.Assay is infrastructure, not a validated application, and we will not claim otherwise. It provides attributable identity, evidenced competence and durable outcome records that support your validation approach. Qualification of the overall computerised system remains yours.
No. Attestations carry a task type, an outcome, an optional counterparty and an optional evidence hash you compute. The underlying records stay in your systems.
It contributes to attributability and to competence evidence for automated actors. It is one input to a compliance position, not a compliance product, and should be assessed as such by your quality function.
It tunes recency, failure penalty, verification requirements and volume sensitivity for a low-tolerance regulated setting. Exact parameters are public at /v1/admin/trust-presets.