Central audit log
The Audit Log brings governed actions with Evidence and lightweight MCP resource reads into one read-only timeline.
Access and scope
Section titled “Access and scope”Only platform admins can open Administration → Audit Log. The separate auditor role grants cross-room access to decisions; it does not grant platform-management or Evidence access.
What the timeline shows
Section titled “What the timeline shows”Evidence Bundle events and MCP resource reads have separate labels. Bundles show their actual signed or unsigned state; read events remain deliberately lightweight and outside the signed Evidence chain. Outcome labels distinguish a policy stop or a refused login (error tone) from an accepted relation whose activation is deferred because its effect is not built yet (calm tone); the recorded status value stays visible as a tooltip. List timestamps use your local time zone, Evidence details use UTC, and both clocks say so. Evidence details count the records the answer actually cited apart from those that only stood in the prompt as context (Cited and Context only); a bundle written before that flag existed shows one neutral Sources count and makes no citation claim.
Filtering and paging
Section titled “Filtering and paging”Filter by source, concrete event type, room, local date range, actor, agent or client ID, and outcome. The type filter offers the vocabulary this installation records (it travels with the response, not as a copy); the outcome filter offers the same vocabulary the list displays, and the blocked option matches policy stops and deferred activations alike, because they share one recorded status. Results are ordered newest first and can be paged without changing the selected filters.
Evidence and privacy
Section titled “Evidence and privacy”Open an Evidence event to inspect its existing bundle. Audit-list rows never contain bundle payloads, raw prompts or raw outputs; prompts and outputs remain represented by hashes in the bundle.
Resource-read logging is best effort and intentionally has no signed bundle. The timeline therefore distinguishes those reads instead of presenting them as full Evidence.