Agentis Solution
Audit-Ready Margin Governance for SOC 2 and Internal Controls
Auditable margin enforcement with per-order policy logs, segregation-of-duties controls, and SOC-2-ready reporting, turning margin governance from a tribal-knowledge function into a documented internal control.
The Problem
Ecommerce CFOs at companies pursuing SOC 2 certification, preparing for IPO, or supporting Series C+ fundraising face a documentation gap on financial controls. Existing margin processes rely on after-the-fact reconciliation and tribal knowledge: 'we look at the margin variance report monthly and investigate exceptions.' That process does not generate the per-transaction audit trail that SOC 2 controls testing requires, and it does not provide segregation of duties between policy authors and runtime operators. Without an enforcement layer with built-in audit infrastructure, achieving SOC 2 readiness on margin controls means custom documentation work that slows certification by months.
How Agentis Solves It
Agentis ecommerce compliance and SOC 2 audit support layer logs every policy evaluation with full inputs, outputs, and rule version applied, generating the per-transaction audit trail that controls testing requires. The platform enforces segregation of duties between policy authors (typically finance), policy approvers (typically CFO or controller), and runtime operators (the system itself). Policy changes follow an approval workflow with immutable history; runtime decisions are logged with cryptographic provenance. The audit log is exportable in formats compatible with SOC 2 evidence requests and standard audit tooling.
Key Benefits
- Cut SOC 2 readiness time on margin controls from months to weeks by leveraging built-in audit infrastructure
- Provide per-transaction evidence that every order was evaluated against approved margin policy
- Establish segregation of duties between policy authors, approvers, and runtime operators
- Support pre-IPO and Series C+ fundraising diligence with documented financial controls on margin
Platform Features
- —Immutable per-evaluation audit log with policy version, inputs, decision, and outcome
- —Approval workflow for policy changes with multi-step review for high-impact policies
- —Segregation-of-duties controls separating policy authoring, approval, and runtime
- —Audit-friendly exports in CSV, JSON, and Parquet formats compatible with major audit tooling
- —Quarterly controls report with policy effectiveness, exception rates, and override frequency
- —Mapping documentation between Agentis policies and SOC 2 control objectives
Built for
Ecommerce CFOs and finance leads at companies pursuing SOC 2 Type II, preparing for IPO, or undergoing Series C+ diligence
Frequently Asked Questions
Does this replace a SOC 2 audit firm?
No. Agentis provides the technical infrastructure that supports SOC 2 controls testing on margin enforcement. You still engage a CPA firm to perform the SOC 2 audit. The Agentis audit log and policy registry are designed to map directly to control objectives, making the audit firm's testing significantly faster than reviewing a custom-built reconciliation process. What the platform contributes is the evidence: every policy evaluation is logged with full inputs, outputs, and the rule version applied, and policy changes carry an immutable approval history. The audit log is exportable in CSV, JSON, and Parquet formats compatible with major audit tooling, and mapping documentation links Agentis policies to SOC 2 control objectives. The CPA firm still designs the audit scope, performs the testing, and issues the report. For your store, the practical division is that Agentis produces the per-transaction trail and the controls documentation, while your audit firm decides what to sample and attests to the result.
What SOC 2 control objectives does this map to?
Most directly to processing-integrity controls (orders are processed against approved policies, exceptions are logged and reviewed) and to a subset of confidentiality and availability controls. The platform also supports change-management controls via the policy approval workflow. We provide documented mappings to specific SOC 2 trust services criteria as part of the standard onboarding for compliance-focused customers. The processing-integrity mapping rests on the immutable per-evaluation audit log, which records policy version, inputs, decision, and outcome for every order. Change management is supported by the approval workflow, which requires designated approvers and keeps the full history of each policy version, approver, and effective date. Segregation-of-duties controls separate policy authoring, approval, and runtime, which auditors typically look for when testing who can change a financial control. The quarterly controls report adds policy effectiveness, exception rates, and override frequency as ongoing evidence. Bring your auditor's control matrix to onboarding so the mapping documentation can be aligned to the criteria your store is actually being tested against.
How are policy approvals handled?
Policy changes follow a configurable workflow: policy author proposes the change, designated approver(s) review and approve, then the policy is promoted to enforce mode after a configurable delay (typically 24h). High-impact policies (affecting more than X% of orders) require additional approval steps. The full history of each policy version, approver, and effective date is immutable and exportable. The workflow is the mechanism behind segregation of duties: policy authors, typically finance, propose; approvers, typically the CFO or controller, sign off; and the runtime, the system itself, applies whatever is currently in enforce mode. The configurable delay before promotion gives finance a window to catch an error before it affects live orders. The approval history is exportable in the same formats as the evaluation log, so an auditor can trace any enforced policy back to who approved it and when. Configure the delay and the high-impact threshold to match the change-control standards your store already follows.
Can auditors export the data they need without involving engineering?
Yes. The audit interface provides self-service export of policy evaluations, policy version history, and approval logs in standard formats (CSV, JSON, Parquet). Auditors with read-only access can pull evidence for specific time windows, transaction IDs, or policy versions without engineering involvement. The interface is designed to match the workflow auditors actually use during fieldwork. Each exported evaluation record contains the policy version, the inputs, the decision, and the outcome, so an auditor can trace a single order from cart to enforcement decision without asking for a database query. Policy version history and approval logs export in the same formats, which lets the auditor pair a runtime decision with the approval that authorized the policy behind it. Because the log is immutable, the exported evidence matches what the system actually did at the time. Grant your auditors read-only access at the start of fieldwork so your store's engineering team stays out of the evidence-gathering loop entirely.
Free Audit, No Commitment
Protect Every Order's Profit Margin
See exactly how much margin Agentis can recover for your store in 7 days, no commitment required.