See Who Changed What And Why

Audit Trails tie every MergeLoom-routed change back to the ticket, run, requester, repository, provider path, validation output, and PR/MR.

AI spend and AI-written code stay out of throwaway chat history. MergeLoom keeps receipts attached to the work.

Ticket EvidenceRun IDRequesterProvider PathValidationChanged LinesPR/MR Link
Evidence Chain
Product Map
  1. Step 01
    Approved Ticket
  2. Step 02
    Run Evidence
  3. Step 03
    Code Audit
  4. Step 04
    PR/MR Review

AI Code Without Receipts Is A Risk

When AI work happens outside the workflow, teams lose the link between the request, the run, the validation evidence, and the final code.

No Ticket Link

A commit does not show which approved work item authorized the AI-generated change.

No Run Receipt

Agent logs, validation output, repair attempts, and review notes disappear into local sessions.

No Provider Trail

Security teams lose the worker or provider trail behind the change.

No Line-Level Proof

Repository metrics cannot answer which lines came through the AI workflow.

Follow The Story From Ticket To Diff

MergeLoom keeps workflow evidence connected so teams move from a changed line back to the ticket, run, checks, and PR/MR behind it.

Ticket Link
Attached
Run Record
Complete
Code Evidence
Line-Level
Review Control
Human
Request Origin

Start With The Approved Work

Every routed change keeps the request, run, user, repository, and provider path connected.

Ticket
Source

Approved work item, requester, acceptance criteria, and status.

Run
Receipt

Run ID, workspace, repository, worker, duration, provider path, and outcome.

Validation
Evidence

Quality Agent output, checks, repair attempts, review notes, and Diff Guard.

PR/MR
Review

Code host branch, summary, reviewer handoff, and final merge decision.

Evidence Chain

Ticket To Diff

Follow the trail from business request to changed line without replacing Git or code review.

Traceable
  1. Evidence 01
    Linked
    Approved Work Item

    The run links back to the exact ticket, issue, or task that authorized it.

  2. Evidence 02
    Saved
    Run Record

    Requester, repository, worker, provider path, status, timing, and outcome are retained.

  3. Evidence 03
    Attached
    Validation Evidence

    Checks, repair attempts, AI review notes, and Diff Guard stay attached.

  4. Evidence 04
    Traceable
    Changed Lines

    Code Audit connects file-level and line-level changes back to the routed run.

  5. Evidence 05
    Human
    PR/MR Review

    Reviewers approve through GitHub, GitLab, or Azure Repos as normal.

Audit Views

Proof For Different Teams

Controller, ticket, code, and worker records answer different questions without hiding the merge decision.

Controller Audit

Workspace-level view of runs, users, repositories, usage, and outcomes.

CloudWorkspace
Ticket Audit

The work item view shows run history, status, evidence, and PR/MR links.

TicketRun
Code Audit

Repository and file views show line-level evidence for routed changes.

FilesLines
Worker Records

Self Hosted teams keep deeper execution traces inside their boundary.

Self HostedWorker
Compliance Proof
Ticket to line
Provider Trail
Recorded
Review System
Code host
Attribution Scope
Routed work

Receipts Without Replacing Git

Audit Trails add AI workflow evidence without replacing code review, Git history, blame, approval, or release controls.

Line-Level Context

Changed lines tie back to the ticket, run, user, timestamp, status, and PR/MR evidence.

Three Audit Views

Controller Audit, Ticket Audit, and Code Audit answer different operational questions.

Run-Aware Records

Cloud Hosted centralizes audit in the controller. Self Hosted keeps deeper execution detail on the worker.

Reviewer Control

The audit trail explains the automation path. The code host remains the approval system.

Untracked Local AI

  • AI Involvement Disappears Into Normal Commits
  • Validation Evidence Lives In Chats Or Terminals
  • Security Teams Cannot Trace Request To Changed Line

MergeLoom-Routed Changes

  • Ticket, Run, User, Provider Path, Validation, And PR/MR Evidence Stay Connected
  • Code Audit Shows Line-Level Evidence
  • Humans Still Review And Merge In The Code Host

See Who Changed What And Why

Audit views show the ticket, requester, run, repository, validation result, PR/MR, and changed lines behind each routed change.

MergeLoom Code Audit screen showing repository and file-level evidence for AI-written code.
Code Audit view for repository and file-level evidence.
MergeLoom activity run screen showing ticket execution, validation, and review status.
Run detail view showing ticket execution, validation, review status, and produced output.

Be Clear About What Is Tracked

Attribution is only useful when the boundary is clear. MergeLoom tracks work routed through MergeLoom workflows.

  • Routed Work Only

    Strong attribution applies to AI work routed through MergeLoom workflows.

  • Code Host Review Remains

    Use GitHub, GitLab, or Azure Repos for review, approval, blame, and merge decisions.

  • Cloud Audit Location

    Cloud Hosted audit is available in the customer controller.

  • Self Hosted Audit Location

    Self Hosted Ticket Audit, Code Audit, and deep traces are worker-owned.

Use Audit Trails When AI Work Needs Proof

Audit Trails are strongest when leaders need proof behind AI-assisted changes without slowing normal PR/MR review.

Compliance Review

Trace changes back to ticket, run, requester, and validation evidence.

Security Review

Understand which worker or provider path produced a change.

Engineering Governance

See how much code was touched through MergeLoom workflows.

Reviewer Context

Give developers evidence before they inspect the diff.

Cloud Hosted Teams

Use controller audit surfaces for central visibility.

Self Hosted Teams

Keep execution evidence in the worker boundary.

Audit Trail FAQ

Does MergeLoom Attribute All AI Code Everywhere?

No. Strong attribution applies to work routed through MergeLoom. Unmanaged local AI usage outside MergeLoom is not captured automatically.

Does Code Audit Replace Git History?

No. Git and the code host still handle review, blame, approval, and merge. Code Audit adds AI workflow evidence.

Where Does Audit Evidence Live?

Cloud Hosted audit lives in the customer controller. Self Hosted execution audit, Code Audit, and deep traces stay worker-owned.

What Do Teams Answer With Audit Trails?

Teams see what changed, which ticket authorized it, who requested it, where it ran, which checks ran, and which PR/MR received the output.

Start Free With No Risk

Pay For Outcomes, Not Seats

Run MergeLoom on scoped work before rolling it out. You only pay when a run opens a PR/MR for review, not for seats or tickets that stop before handoff.

Cloud

50 Free PR/MR Runs

Then From £4 Per PR/MR

Self Hosted

50 Free PR/MR Runs

Then From £2 Per PR/MR

Paid Outcomes

Only PR/MR Runs Count

No PR/MR, No Run Charge

  • Free To Start
  • Pay For Outcomes
  • No Lock-In Contracts
  • No Credit Card Required (Self-Hosted)
  • Cancel Anytime

No PR/MR, No Run Charge · No Seat Pricing · Human Review Stays In Control

See Pricing