Skip to content

Audit trail

Every decision and step is written to the audit trail. It is revision-safe: entries are only ever appended, and each one includes the hash of the entry before it.

FieldContent
seqsequence number, starting at 1
tsISO timestamp
actorwho acted, e.g. agent:triage or a user
actione.g. policy.decision, step.tool_call, approval.decided, run.completed
target, runIdwhat was acted on, in which run
payloadthe details, redacted before hashing
payloadDigestSHA-256 of the payload
prevHashhash of the previous entry (64 zeros for the first)
hashSHA-256 over the canonical JSON of the fields above

Canonical JSON means sorted keys and no whitespace, so anyone can recompute a hash.

Periodically a checkpoint {seq, hash, ts, keyId} is signed with an Ed25519 key from the configuration. A checkpoint anchors everything before it: even someone with database access cannot rewrite history without the signing key.

Verification walks the chain and reports hash_mismatch, broken_link, gap, payload_mismatch, checkpoint_signature, checkpoint_mismatch or unknown_key. The local CLI verifies the chain of every run and prints audit: valid (N entries, head …).

Coming with the API The table is append-only: the platform’s database role has no UPDATE or DELETE privilege on it, and a trigger rejects both.