Private Alpha

Evidence and audit

How Ethen records evidence of actions, maintains audit trails, and supports accountable operations.

Raw

Ethen records an evidence trail of actions taken by agents, tools, and the approval framework to support accountability and post-hoc review.

Audit entry lifecycle

Every auditable action produces an AuditEntry with:

  • Event type and label
  • Actor identity
  • Timestamp
  • High-level outcome

Before export, audit entries pass through a sensitive-metadata filter that strips fields matching secret, token, key, credential, authorization, cookie, body, header, or session patterns. Metadata that survives the filter includes:

  • AUDIT_EVENT_LABELS — human-readable labels for each event type
  • Timestamp and actor ID
  • Outcome (success / failure / pending)
  • Resource identifiers (agent ID, session ID, tool ID)

Evidence packages

When an approval request is created, it can carry an evidence package — structured data collected about the proposed action before a human makes a decision. See the approval governance guide for the evidence package schema.

Payload integrity

The approval framework uses SHA-256 payload hashing to bind approval decisions to exact content. When the underlying payload changes after approval, the request transitions to stale status and must be re-submitted. This prevents:

  • Approving content that was subsequently modified.
  • Replaying stale approvals against different payloads.
  • Accidental execution against outdated state.

Audit export

The audit-export module provides filtered export of audit records:

  • Sensitive metadata is stripped before export (see the filter rules above).
  • The getSessionAuditLog function returns records scoped to a specific session.
  • The getRecentActivityLog function returns records across sessions within a time window.

See also

Last verified 2026-07-10 · Owner platform-team