D7 · See, govern, and prove Shipped

Audit

What it does

Every authorization decision recorded, tamper-evident; a forensic, assurance-grade record.

Every authorization decision is written into a per-tenant, hash-chained record where each entry seals the previous one. One-click verification proves the chain was not altered, so the log is evidence rather than a claim.

When it applies

Always on, on every decision, from the moment the gateway is live.

How it works

Every decisionallow / hold / denyAudithash-chainedTamper-evidentindependently verifiable

Every authorization decision is written to a hash-chained log where each entry's hash depends on the previous, so any alteration breaks the chain and is detected on verification.

In practice

A dispute over what an agent did is settled from the record, which cannot be altered without detection.

What you get

The chain itself is the evidence, verifiable on demand from the Audit verify screen.

Why it matters

A forensic, assurance-grade record, not a dashboard you have to trust.

An authorization control is only trusted if its record cannot be altered, a plain log can be edited, a tamper-evident one cannot without detection. This gives you a forensic, assurance-grade record that stands up in an investigation or an audit.

Talk to us →