Every Release Needs a Chain of Custody. AI Agents Just Made That Harder.

When an auditor asks what went into your last release, most teams do the same thing. They open four tabs:

  • GitHub for commits 
  • Jira for tickets
  • A Slack thread for the approvals
  • A spreadsheet to track what made it to production (built two sprints ago)

None of it connects. None of it is bound to the release. And none of it was built to satisfy a regulator. It was built to ship software.

Attempting to reconstruct what shipped across GitHub, Jira, Slack, and a spreadsheet is the real compliance problem. Not the lack of policy. Not the lack of tools. The lack of a connected, signed, auditor-ready record that traces every release back to the commits, PRs, Jira tickets, and approvals that produced it.

AI agents made this harder. Developers using Cursor, Claude Code, and other agentic tools now commit code that no human wrote and no DevOps record tracks. The session behind the commit leaves no trace anywhere in your pipeline: not the prompts, not the decisions, not the intent. Your Git log is complete, but your compliance picture is not.

Regulators are not waiting. From NIST SSDF to the EU Cyber Resilience Act, every framework demands the exact same thing: proof. They want to know who wrote the code, who approved it, what ticket drove it, and when, all signed, connected, and attached to the release. 

With agents now contributing code alongside developers, most teams piece together the audit trail fast enough. That is the evidence gap most organizations are only now realizing they have. The cost of that gap is real: personal liability for CISOs, failed audits, blocked deals, and CRA fines of up to 2.5% of global revenue.

How JFrog AppTrust Assembles the Evidence Chain Automatically

At swampUP 2026, JFrog is launching Prompt to Release Traceability inside JFrog AppTrust. For every release, AppTrust automatically pulls together the commits, PRs, Jira tickets, and approver records that produced it, signs them, and attaches them to the release before any promotion gate runs. No manual assembly. No screenshots. Proven evidence, ready when an auditor asks.

Screenshot of the JFrog Platform AppTrust tab displaying application version PR evidence.
AppTrust PR evidence: 5 resolved commits, 2 PR attestations, 0 stale approvals, automatically collected and signed.

 

AppTrust assembles three evidence layers automatically and attaches them to your application version before any promotion gate runs.

  1. Jira tickets, validated on transition: AppTrust does not just check whether a Jira ticket exists; it validates the full transition history: from ticket creation, to in-progress, to done, complete with dates. An auditor does not accept a closed ticket; they demand proof of the workflow.
  2. Commits and PRs, signed and connected: For every release, AppTrust identifies the commits that went into it and maps them to their Pull Requests in GitHub. For each PR, AppTrust captures who merged, who approved, and whether the approver was the same person as the committer. That last check matters: most compliance frameworks explicitly prohibit self-approval, and most teams have no automated way to catch it today.
  3. Agent session evidence: That audit trail used to be enough for most releases, but AI changed the game. Incoming JFrog Agent Plugins will capture every agent interaction at the source and store it as signed evidence in Artifactory. Governance starts before the first commit, not after. That includes not just the prompts and code produced, but the full session bill of materials: which MCPs, skills, and agentic assets the agent used to build the release.

From Two Weeks of Manual Assembly to Minutes

Before Prompt to Release Traceability, a compliance audit meant two weeks of manual evidence assembly across GitHub, Jira, and your CI pipeline, if you could find all the pieces.

Now, AppTrust can assemble the signed evidence chain automatically at promotion time. Every commit, PR, Jira transition, and approver record is signed, timestamped, and attached to the application version that shipped. When an auditor asks, AppTrust delivers the signed package in minutes.

For teams running agentic development at scale, this is the difference between a release you can prove and one you can only hope is compliant. That is DevGovOps in practice: governance that ships with every release, invisible to developers, always visible to auditors.

Get Started with Prompt to Release Traceability

We also launched Out-of-the-Box Compliance Frameworks at swampUP 2026: pre-mapped controls for NIST SSDF and the EU Cyber Resilience Act, ready to enforce without manual configuration. Prompt to Release Traceability is the data layer that makes those frameworks run. Without the evidence, the controls have nothing to evaluate against.

Prompt to Release Traceability is generally available now. Git data (commits, PRs, Jira ticket transitions, and approver chains) ships today. Agent session evidence and the session bill of materials arrive later this year. The regulations are here, and your next audit won’t wait. With JFrog AppTrust, your evidence chain is ready.

Book a demo at jfrog.com/demo | Explore JFrog AppTrust at jfrog.com/apptrust