Enterprise procurement is asking new questions
Until 2024: "is your product SOC 2?". Now: "is your product's AI activity SOC 2?". The question is increasingly asked by procurement teams of major enterprise customers. Your answer determines whether you progress to contract or get held up indefinitely. The default answer ("we don't have AI activity logs") is increasingly disqualifying.
White-label receipt issuance
Enterprise tier ships white-label receipt issuance. Your AI features issue receipts signed by your domain (not by genzagents.com). Your customers verify against your /did.json. The audit pattern is identical to ours; the brand is yours. Customer-facing receipt verification = your product's audit story.
Customer-facing audit panel
Within your product UI: a per-customer "AI activity" panel. Lists every AI-mediated action this customer triggered, with date, action type, model used, cost, receipt ID. Backed by /v1/receipts queries scoped to the customer's identity. Drop-in React component or copy + customise. Your customer's compliance team gets the audit they've been asking for.
Evidence packs for customers' audits
When your customer's SOC 2 / ISO 42001 audit asks "what audit trail do you have for your vendors' AI activity?", they can request a per-customer evidence pack from your product. The pack is signed; it includes only their data (ACL-scoped); it satisfies their audit. Differentiator vs SaaS competitors without an audit story.
Operational scenario: AI-powered analytics
Your SaaS has AI-powered analytics. Each AI query generates a receipt for the customer. The audit panel shows them "AI activity on your data: 47 queries in the last 30 days; here are the receipts". When their compliance team asks "what does your vendor's AI do with our data?", the answer is verifiable.
Operational scenario: customer service AI
Your SaaS has AI customer service. Each AI interaction is a receipt. The audit trail satisfies EU AI Act §50 transparency for the customer-facing chatbot use case. When your customer's compliance team asks for transparency evidence, you ship them a receipt query API.