Documentation agents
Agent-written docs, under change control.
READMEs, API references, ADRs, and runbooks update in the same PR as the code that changed them — attributed, reviewed, and recorded in the same evidence as every other change.
PR merge evidence digest · sample from a demo workspace
## AutoDevOps merge evidence
Session: claude-session-fincard-demo-002
Repository: fincard-network-verifier
Decision: confirm → approved
- Policy: fincard-demo-2026-04-20
- Approval: audit-fincard-004
- Intent fidelity: 0.94 (event: intent.fidelity.scored)
Digest: sha256:a4e8…9b2fThe same evidence as code PRs, bound to one audit record.
01Controls evidenced
Docs change like code. Evidence them like code.
A generated runbook is a change to a controlled system. It carries the same attribution and change-management evidence as the diff beside it.
- FFIEC.SDLC-02Verifier-checkable
Attributed SDLC Code Provenance
FFIEC Development & Acquisition Booklet: Software Development Lifecycle Integrity
Catalog entryHow the session record supports it
Pull request (PR) evidence can bind recorded sessions, commit hashes, policy decisions, and Check Run results into one digest.
PR Merge Evidence Summary / GitHub Check Run
- SOC2.CC8-03Verifier-checkable
Cryptographic Evidence Package Verification
SOC 2 Common Criteria 8.1: Change Management & System Integrity
Catalog entryHow the session record supports it
Evidence exports use manifests and SHA-256 digests. Persisted exports record append-only chain entries.
Evidence Package Manifest / Local Verifier Transcript
02The fix
Docs that go through the same gate as code.
- Same workflow as code
- Doc updates land in the commit or PR that changed the behavior.
- Reviewable before merge
- Approve or reject the generated doc inside the PR; the decision lands in the audit record.
- Template-aware generation
- Repo structure and team templates produce docs in your existing format.
03Artifacts
What the agents keep current
READMEs and onboarding
Install steps, commands, and workflows update in the PR that changed them.
API references
Contract-facing docs update when schemas, routes, or integration behavior change.
ADRs, release notes, runbooks
Capture rationale while the diff context is still fresh.
Session replay
FinCard demo

Doc-changing agent runs stay tied to session replay, findings, and approval state.
04Who benefits
Three stakeholders, one record
- Engineering leads
- Onboarding docs and runbooks that reflect what shipped.
- Security teams
- Every runbook change carries an approver, a decision, and an audit record.
- Platform engineers
- Set the doc template and policy once; every repo’s generated docs follow it.
Stop treating docs as a separate workstream
Reviewed in the PR, recorded in the same audit trail as the code, evidenced against the same change controls. Start with one repo.