Postgres now reports custody_class=operational with a cited 30-day recoverable window. Join ITC-CAP operations.audit at D4, publish the interface card, and overlay user-engine tenants [*] from Git so an ExternalSecret refresh cannot shrink it.
22 lines
583 B
YAML
22 lines
583 B
YAML
version: 1
|
|
updated: '2026-08-16'
|
|
domain: infotech
|
|
capabilities:
|
|
- id: capability.audit.event-retain
|
|
name: Audit Event Retention
|
|
summary: Collect, normalize, retain, and search audit events with integrity evidence
|
|
across tenants.
|
|
joins: operations.audit
|
|
provision: data/capability/audit-core-operational.json
|
|
vector: D4 provision / A4 / C3 / R2
|
|
domain: infotech
|
|
status: production
|
|
owner: audit-core
|
|
path: registry/capabilities/capability.audit.event-retain.md
|
|
tags:
|
|
- audit
|
|
- retention
|
|
- compliance
|
|
consumption_modes:
|
|
- http ingest
|
|
- source module
|