
# Evidence and audit

Ethen records an evidence trail of actions taken by agents, tools, and the approval framework to support accountability and post-hoc review.

## Audit entry lifecycle

Every auditable action produces an `AuditEntry` with:

- Event type and label
- Actor identity
- Timestamp
- High-level outcome

Before export, audit entries pass through a sensitive-metadata filter that strips fields matching secret, token, key, credential, authorization, cookie, body, header, or session patterns. Metadata that survives the filter includes:

- `AUDIT_EVENT_LABELS` — human-readable labels for each event type
- Timestamp and actor ID
- Outcome (success / failure / pending)
- Resource identifiers (agent ID, session ID, tool ID)

## Evidence packages

When an approval request is created, it can carry an **evidence package** — structured data collected about the proposed action before a human makes a decision. See the [approval governance guide](/docs/security/approval-governance) for the evidence package schema.

## Payload integrity

The approval framework uses **SHA-256 payload hashing** to bind approval decisions to exact content. When the underlying payload changes after approval, the request transitions to `stale` status and must be re-submitted. This prevents:

- Approving content that was subsequently modified.
- Replaying stale approvals against different payloads.
- Accidental execution against outdated state.

## Audit export

The `audit-export` module provides filtered export of audit records:

- Sensitive metadata is stripped before export (see the filter rules above).
- The `getSessionAuditLog` function returns records scoped to a specific session.
- The `getRecentActivityLog` function returns records across sessions within a time window.

## See also

- [Approval governance](/docs/security/approval-governance)
- [Data handling and retention](/docs/security/data-handling)
- [Enterprise controls](/docs/enterprise/enterprise-controls)
