Skip to content
Jetrepo
Esc
navigateopen⌘Jpreview
On this page

Review audit provenance

Trace a Candidate through policy, Approval, Operation, revisions, outcome, and delivery impact.

Open Audit to inspect transactional evidence for the selected Environment. Reading this workspace requires scoped audit.read; server authorization applies even when a direct URL is used.

With operation.read in the same Environment, rows include the requested actions from loaded Candidate summaries, and opening a row retrieves its exact Candidate. If that permission or evidence is unavailable, Audit marks the requested-work summary unavailable while retaining the event evidence your role may read.

Trace a change

  1. Search loaded events by action, visible actor name, principal, agent/client, Candidate, Operation, or correlation ID. Use Status and Actor to narrow the list. The count states how many events are loaded; these are local filters, not a search of all retained history.
  2. Open a row to see who acted, when, the policy decision, any recorded human decision, and failure details. Expand Technical identifiers and policy evidence for principal/credential identity, delegation, correlation ID, Candidate digest, policy versions, revision IDs, and the exact Operation outcome. Each row is one durable Operation version.
  3. Follow Operation or Candidate to inspect the authoritative resource and its full transition or diff evidence.
  4. Select Load older evidence to extend the timeline. This remains available when no loaded events match your filters.

Normalized argument values are not displayed. Audit shows their durable digest and sorted field names, which proves the execution binding without exposing Content or credentials. Outcome values receive the same treatment; revision, policy, identity, manifest, and delivery provenance remain exact.

Canonical Operation evidence is written transactionally with the state transition. A required audit or outbox write failure prevents the consequential state change from silently committing. Recovery and rollback create new Candidates and evidence rows rather than rewriting old history.

Audit is operational evidence, not a replacement for an operator’s retention, export, or SIEM policy. Correlate the displayed correlation ID with self-hosted logs when investigating infrastructure outside the canonical runtime.

Was this page helpful?