DocumentationEvidence & usage

Governance audit log

Inspect administrative changes separately from runtime decisions and notification delivery.

Updated 2026-09-22 Read as Markdown
On this page

Choose the right record

Use Activity for runtime decisions and their action context. Use Audit for supported governance and administrative activity, such as policy and access-management changes. Use checkpoint records for the approval lifecycle, and webhook delivery records for outbound event attempts.

These records answer different questions. A successful webhook delivery does not prove that the recipient enforced a decision; a runtime ALLOW does not prove that the upstream operation succeeded.

Investigate a change

Select the intended workspace and time range, then inspect the actor, action, target, and recorded context. Correlate a policy change with its revision and a runtime decision with its matched policy. Check the available scope before treating the absence of an event as proof that nothing changed.

Verify the recorded chain

Use the available audit verification workflow and inspect its selected range and result. Verification relies on the implemented service-held key mechanism and records included in the check. It is distinct from independently proving capture completeness or customer identity claims.

Prepare review material

Choose an evidence export appropriate to the review and include its verification information and scope. Retain the distinction between administrative audit activity, runtime decisions, and approval records in your explanation to the reviewer.

Decision records · Evidence exports · Workspaces and roles.