| capability.audit.event-retain |
Audit Event Retention |
Collect, normalize, retain, and search audit events with integrity evidence across tenants. |
audit-core |
production |
infotech |
| audit |
| retention |
| compliance |
|
| itc_cap |
provision |
provision_maturity |
| operations.audit |
data/capability/audit-core-operational.json |
D4 |
|
| completeness |
reliability |
| level |
name |
confidence |
basis |
satisfied_expectations |
broken_expectations |
out_of_scope_expectations |
| C3 |
Substantial |
medium |
live_receiver_and_restore_walk |
| HTTP ingest through the backend contract |
| append-only Postgres custody on platform-pg |
| recovery cited to the live platform data.backup provision |
|
| data.archive sink not provided |
|
| application business audit semantics ownership |
| booked-cost origination |
|
|
| level |
confidence |
basis |
known_reliability_risks |
| R2 |
medium |
failure_matrix_and_restore_walk |
|
|
|
| intent |
includes |
excludes |
use_cases |
| Provide independent audit fabric for collecting, retaining, searching, and proving integrity of audit events.
|
| audit ingestion |
| retention policy |
| search and export |
| tamper evidence |
|
| generating domain business events |
| procuring or operating platform backup |
| booked financial facts |
|
|
|
| current_level |
target_level |
current_artifacts |
consumption_modes |
| A4 |
A5 |
| audit-core/deploy/audit-core.yaml |
| audit-core/audit_core/postgres_backend.py |
| rapp-postgres/consumers/audit-core.yaml |
|
| http ingest |
| source module |
|
|
| depends_on |
related_to |
uses_provisions |
|
|
| capability.activity.event-coordinate |
| capability.statehub.progress-log |
|
| data.transactional (rapp-postgres/platform-pg) |
| data.backup (resource:platform:audit-storage, cited) |
| security.secrets (OpenBao / ESO) |
|
|
| recommended_for |
not_recommended_for |
known_limitations |
| platform and application audit event delivery over POST /v1/events |
|
| treating this store as WORM archive |
| replacing application-level logging only |
|
| recoverable history is the 30-day platform backup window |
| no hash-chain or export API yet |
|
|