A shared action log would make the setup much easier to audit, especially when several specialists are involved. I’d take it one step further and attach the verification evidence to each action as well—not just which agent ran the command, but what observable state changed afterward. That would help distinguish “the command executed” from “the requested outcome actually happened.” It could also make disagreements between agents much easier to resolve because the system has a common evidence trail rather than relying on each agent’s interpretation of the result.