The AI Confirms Before It Changes Anything — and Logs Every Change

July 6, 2026 · InfraScout Team

An InfraScout assessment does more than look at your estate — it can also change it, running a remediation or adjusting a configuration when you ask. Two improvements in this release govern how those changes happen. In a live conversation, the AI now tells you exactly what it is about to change and waits for your go-ahead before it acts. And every change it makes — or notices has already happened — is recorded automatically, so you always have a dated record of what changed and where.

It tells you what will change, then waits for your go-ahead

Reading is safe; changing is not. So the AI now draws a hard line at the moment a change would happen. Before it runs a remediation, modifies a configuration, or takes any other action that alters state, it stops and lays out the plan in plain terms: what will change, on which hosts or cloud resources, and what impact to expect. Only after you give an explicit go-ahead does it actually make the change.

This is a confirmation step, not a speed bump on everything the AI does. The read-only work that makes up most of an assessment — inventorying hosts, pulling configuration, checking sign-ins — flows exactly as before. The pause is reserved for the actions that carry consequences, which are precisely the ones you want to see coming. You get the plan, the blast radius, and the expected effect up front, and nothing changes until you say so.

Scheduled workflows run unattended

The confirm-first behavior is for live conversations, where someone is at the keyboard to answer. A scheduled Agentic Workflow is unattended by design — it runs on a schedule or trigger precisely so no one has to watch it — so a workflow run does not stop to ask and continues straight through. Reserve state-changing workflows for changes you have already decided to allow.

Every change is written to a dated change log

A confirmation keeps you in control at the moment a change happens. The change log keeps a record of it afterward. Whenever the AI makes a change — and also when it simply notices that something has already changed since it last looked — it writes a dated entry to the affected host's change log, capturing what changed and when.

Changes that reach beyond a single host are recorded at the right level too. Anything environment-wide, or anything that affects a whole connected cloud tenant, is written to a new environment-level change log alongside the per-host ones. Between the two, a change lands in the log that matches its reach: host-specific work on the host, tenant-wide or cross-cutting work in the environment log.

Both logs live in the AI's persistent memory — the same store you already inspect on the Memory admin page — so there is no new system to learn and no separate place to check. A change-log entry shows up, renders, and is browsable exactly like any other memory entry, right next to the environment metadata and assessment status the AI already keeps there.

Sharper troubleshooting, start to finish

Alongside the guardrails on making changes, the AI got more disciplined about the investigation itself. It plans its approach before it starts running commands rather than reaching for the first tool that comes to mind. When it turns up a problem, it follows the thread to the root cause instead of stopping at the first symptom. And before it reports a finding, it checks that every claim traces back to something a tool actually returned, so what you read is grounded in evidence rather than inference.

It is also more candid about its limits. When the AI hits a capability gap it genuinely cannot work around — a system it can't reach, a check the available tools don't cover — it now tells you so plainly instead of guessing or papering over the gap. A clear account of what it could not determine, and why, is more useful in an assessment than a confident answer that does not hold up.

Where you'll find the change logs

Because the change logs live in memory, browsing them is worth a moment. The Memory Files view in the admin portal now renders nested folders as a real, browsable tree. Previously a multi-level path collapsed into a single oddly-named entry, which made a per-host change log awkward to find. Now you expand into it the way you would expect — open a host, open its change log, read the dated entries in order.

The environment-wide change log sits at the top level next to the other environment-scoped entries, so a quick scan tells you what has changed across the estate without opening any single host. See the Memory admin page for a full tour of the store — how entries are organized, and how to filter a large one down to just the host or scope you care about.

Try it

The next time you run an assessment that might change something — a remediation, a configuration fix — watch for the AI to lay out the change and wait for your go-ahead before it acts. Approve it, let it run, then open the Memory view and expand into the affected host to see the change recorded with its date. Confirm up front, verify in the log afterward: that two-part rhythm is the whole point.

Questions or feedback? Reach us at info@infrascout.cloud.