audit-core/registry/capabilities/capability.audit.event-retain.md
tegwick 5fd04e2095 Implement AUDIT-WP-0007 hash-chain integrity.
Accept now extends a single-schema chain. Verify walks it; a rewritten
payload_hash is a break. Tamper evidence is that detector plus an
external chain-head attestation, not WORM.
2026-08-16 01:18:30 +02:00

2.5 KiB

id name summary owner status domain tags joins external_evidence discovery availability relations consumer_guidance
capability.audit.event-retain Audit Event Retention Collect, normalize, retain, and search audit events with integrity evidence across tenants. audit-core production infotech
audit
retention
compliance
itc_cap provision provision_maturity
operations.audit data/capability/audit-core-operational.json D4
completeness reliability
level name confidence basis satisfied_expectations broken_expectations out_of_scope_expectations
C3 Substantial medium live_receiver_and_restore_walk
HTTP ingest through the backend contract
append-only Postgres custody on platform-pg
recovery cited to the live platform data.backup provision
data.archive sink not provided
application business audit semantics ownership
booked-cost origination
level confidence basis known_reliability_risks
R2 medium failure_matrix_and_restore_walk
single replica
intent includes excludes use_cases
Provide independent audit fabric for collecting, retaining, searching, and proving integrity of audit events.
audit ingestion
retention policy
search and export
tamper evidence
generating domain business events
procuring or operating platform backup
booked financial facts
current_level target_level current_artifacts consumption_modes
A4 A5
audit-core/deploy/audit-core.yaml
audit-core/audit_core/postgres_backend.py
rapp-postgres/consumers/audit-core.yaml
http ingest
source module
depends_on related_to uses_provisions
capability.activity.event-coordinate
capability.statehub.progress-log
data.transactional (rapp-postgres/platform-pg)
data.backup (resource:platform:audit-storage, cited)
security.secrets (OpenBao / ESO)
recommended_for not_recommended_for known_limitations
platform and application audit event delivery over POST /v1/events
treating this store as WORM archive
replacing application-level logging only
recoverable history is the 30-day platform backup window
no hash-chain or export API yet

Audit Event Retention

Audit Core provides the operational custody layer for audit events. ITC-CAP join: operations.audit at provision maturity D4 (data/capability/audit-core-operational.json). Maturity is not a property of this abstract capability.