Evidence and audit
How Ethen records evidence of actions, maintains audit trails, and supports accountable operations.
Ethen records an evidence trail of actions taken by agents, tools, and the approval framework to support accountability and post-hoc review.
Audit entry lifecycle
Every auditable action produces an AuditEntry with:
- Event type and label
- Actor identity
- Timestamp
- High-level outcome
Before export, audit entries pass through a sensitive-metadata filter that strips fields matching secret, token, key, credential, authorization, cookie, body, header, or session patterns. Metadata that survives the filter includes:
AUDIT_EVENT_LABELS— human-readable labels for each event type- Timestamp and actor ID
- Outcome (success / failure / pending)
- Resource identifiers (agent ID, session ID, tool ID)
Evidence packages
When an approval request is created, it can carry an evidence package — structured data collected about the proposed action before a human makes a decision. See the approval governance guide for the evidence package schema.
Payload integrity
The approval framework uses SHA-256 payload hashing to bind approval decisions to exact content. When the underlying payload changes after approval, the request transitions to stale status and must be re-submitted. This prevents:
- Approving content that was subsequently modified.
- Replaying stale approvals against different payloads.
- Accidental execution against outdated state.
Audit export
The audit-export module provides filtered export of audit records:
- Sensitive metadata is stripped before export (see the filter rules above).
- The
getSessionAuditLogfunction returns records scoped to a specific session. - The
getRecentActivityLogfunction returns records across sessions within a time window.