Entities

Audit event

An immutable record of an action: actor, action, target, timestamp, and the before and after state where relevant.

Volume

Millions per tenant per period

Retention

Years, beyond the transactional retention

Entity attributes6
  • Append-only, tamper-evident audit log with retention measured in years, held separately from application logging.
  • Append-only, tamper-evident audit log with retention measured in years, held separately from application logging.
  • Identity must federate to the customer's provider, and role assignment history must be retained.
  • audit_event_id
  • Every transactional row must carry a tenant identifier from the outset, even in a single-tenant deployment.
  • Append-only, tamper-evident audit log with retention measured in years, held separately from application logging.
Entity relationships1
Entity lifecycle

Not yet researched

Only the control-bearing entities were modelled for lifecycle. Defensible as a starting point, but it does leave the entity model uneven, and this is incompleteness rather than a finding.