Skip to content

audit

Exposes the framework’s event store as a paginated, filterable audit log via the audit:query:list handler (accessible to Admin and SystemAdmin roles). No separate table or projection — the event store is the audit trail by construction: every entity write already records who, when, what entity, and the event payload with PII stripped. A SystemAdmin can pass scope: "system" to read the app-instance system events such as app.started. Filter by aggregateType, aggregateId, eventType, userId, or time range. Also records audit:event:escape-hatch-used whenever a handler uses one of the framework’s escape hatches (unsafeRaw, acknowledgeCrossTenant, db.global() writes, or a granted identity switch).

What this feature needs to run (Requires).

flowchart TB
  n_audit["audit"]
  subgraph how_reqs["Requires"]
    n_tenant["tenant"]
    n_user["user"]
    n_config["config"]
  end
  n_tenant --> n_audit
  n_user --> n_audit
  n_config --> n_audit

Per-tenant config keys, set via the tenant-admin UI or a seed. 🔒 = encrypted at rest.

KeyTypeDefaultScopeWho can writeWho can read
escape-hatch-retention-daysnumber (≥ 1)90systemsystemTenantAdmin, Admin, SystemAdmin