Audit Logging Policy Planning
Purpose
This page defines future audit logging policy before pull-up/push-up draft storage, staff review records, Morning Sheet visibility, retention/deletion jobs, or account/actor mapping storage exists.
It is planning-only. It creates no live audit logs, audit tables, audit write endpoints, draft storage, staff decisions, retention jobs, deletion jobs, write endpoints, tables, migrations, or stored community content.
Current Storage/Audit Boundary
Product
Renata
The Sixth Sense at 6th StreetAudit logging
false
not implementedDraft storage
false
not implementedWrites
false
not implementedAudit logging policy is planning-only; no audit logs, draft storage, review records, staff decisions, Morning Sheet placements, retention jobs, deletion jobs, tables, migrations, or writes exist.
Why Audit Policy Comes Before Live Writes
Future workflow storage needs a strict audit policy before any live write path exists. Audit metadata must support accountability without becoming surveillance, resident scoring, staff surveillance, or a hidden copy of deleted sensitive content.
No audit event writer, audit table, audit viewer, storage job, retention job, deletion job, active migration, or executable SQL file is added.
Audit Logging Principles
- Audit logging exists to support accountability for system actions, not surveillance of residents.
- Audit logs must be minimal.
- Audit logs must not contain draft bodies unless a future policy explicitly approves a narrowly scoped exception.
- Audit logs must not contain real names, emails, Cloudflare claims, JWTs, tokens, or raw identity headers.
- Audit logs must not become attendance tracking.
- Audit logs must not become participation tracking.
- Audit logs must not become participation analytics.
- Audit logs must not become scoring, ranking, discipline, compliance, or resident performance tracking.
- Audit logs should record event type, pseudonymous actor ref if approved, timestamp, workflow scope, and policy reason where necessary.
- Audit logs must be separated from sensitive draft content where possible.
- Audit logging must be approved before live writes, staff review, retention/deletion jobs, or Morning Sheet placement exist.
Future Audit Event Categories
| Category | Purpose | Status | Active | Sensitivity | Allowed metadata | Prohibited content |
|---|---|---|---|---|---|---|
access-boundary-events | future boolean access-boundary checks only | planning-only | false | boundary-metadata-only | event_type, community_id, workflow_scope, created_at, reason_code | identity claim values, email, name, group claim, JWT, token, raw Access claims |
actor-reference-events | future actor ref creation/status events | planning-only | false | pseudonymous-reference-metadata | event_id, event_type, community_id, actor_ref, status_from, status_to, created_at, reason_code | real identity, email, name, initials, resident profile details, staff profile details |
role-mapping-events | future role mapping changes | planning-only | false | configuration-metadata | event_id, event_type, community_id, workflow_scope, actor_ref, policy_ref, status_from, status_to, created_at | live role assignment records, Cloudflare claims, email, name, attendance data, participation data |
draft-lifecycle-events | future draft status changes | planning-only | false | draft-metadata-without-content | event_id, event_type, community_id, workflow_scope, actor_ref, subject_actor_ref, draft_ref, status_from, status_to, created_at, retention_category | draft body content by default, private feedback content by default, real names, emails, sensitive disclosures |
staff-review-events | future review lane/status changes | planning-only | false | review-metadata-without-notes | event_id, event_type, community_id, workflow_scope, reviewer_actor_ref, draft_ref, status_from, status_to, reason_code, created_at | staff review notes by default, clinical interpretation, resident scoring, discipline points, compliance metrics |
morning-sheet-visibility-events | future visibility eligibility changes | planning-only | false | visibility-metadata-only | event_id, event_type, community_id, workflow_scope, draft_ref, status_from, status_to, policy_ref, created_at | automatic placement, draft body content, public reading text, real identity, ranking data |
retention-deletion-events | future archive/delete/restore events | planning-only | false | retention-deletion-metadata | event_id, event_type, community_id, workflow_scope, draft_ref, retention_category, deletion_marker, reason_code, created_at | content copying into audit logs, deleted sensitive content, private feedback content, raw identity headers |
policy-configuration-events | future configuration changes | planning-only | false | config-metadata-only | event_id, event_type, community_id, workflow_scope, policy_ref, status_from, status_to, reason_code, created_at | resident data, staff profile details, submission content, tracking metrics, scoring data |
ai-use-events | future AI-use policy events | planning-only | false | policy-check-metadata-only | event_id, event_type, community_id, workflow_scope, policy_ref, reason_code, created_at | real submission content unless separately approved, draft body content by default, private feedback content, OpenAI prompts containing sensitive content |
Planned Audit Event Types
| Event type | Status | Implemented | Active behavior | Active storage |
|---|---|---|---|---|
access_boundary_checked | future-only | false | false | false |
actor_ref_created | future-only | false | false | false |
actor_ref_archived | future-only | false | false | false |
role_mapping_planned | future-only | false | false | false |
role_mapping_revoked | future-only | false | false | false |
draft_created | future-only | false | false | false |
draft_status_changed | future-only | false | false | false |
draft_archived | future-only | false | false | false |
draft_deleted | future-only | false | false | false |
review_lane_changed | future-only | false | false | false |
review_escalated | future-only | false | false | false |
morning_sheet_visibility_marked | future-only | false | false | false |
morning_sheet_visibility_blocked | future-only | false | false | false |
retention_category_set | future-only | false | false | false |
deletion_requested | future-only | false | false | false |
deletion_completed | future-only | false | false | false |
policy_config_changed | future-only | false | false | false |
ai_use_policy_checked | future-only | false | false | false |
Allowed Audit Metadata
| Field | Status | Active | Rule |
|---|---|---|---|
event_id | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
event_type | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
community_id | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
workflow_scope | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
actor_ref | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
subject_actor_ref | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
reviewer_actor_ref | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
draft_ref | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
policy_ref | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
status_from | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
status_to | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
reason_code | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
created_at | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
retention_category | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
deletion_marker | planning-only | false | Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written. |
Prohibited Audit Content
Audit Relationship To Retention/Deletion
Minimization
- record the smallest useful event metadata
- separate audit metadata from sensitive draft content where possible
- prefer reason codes over free-text notes
- avoid storing content copies in audit records
- avoid storing identity values or Cloudflare Access claims
- avoid audit fields that can become attendance, participation, scoring, compliance, or resident performance tracking
- keep audit visibility limited until audit visibility policy is approved
Retention relationship
- deleting draft content does not automatically mean deleting all audit metadata
- audit metadata must be minimal and non-sensitive
- audit metadata must not preserve deleted sensitive content
- deleted-record markers may exist only under approved policy
- audit log retention must be shorter or minimal where possible unless policy requires otherwise
Deletion relationship
- permanent deletion rules require privacy/legal/staff review
- rollback/restore events require approved policy
- audit logs must not be used to reconstruct sensitive deleted drafts
- deletion events must not copy draft body, private feedback, staff notes, or raw identity values into audit metadata
- deleted-record markers are planning-only and inactive until deletion and audit policies are approved
Audit Visibility And Reviewer/Admin Boundaries
Audit visibility
- audit visibility policy must be approved before any audit viewer exists
- audit records must not expose real identity values or Cloudflare Access claims
- audit records must not expose draft body content by default
- audit visibility must not become staff surveillance or resident performance review
- no audit UI, export, endpoint, or log viewer exists in this phase
Reviewer/admin boundaries
- reviewers and admins may not use audit metadata for attendance, participation, scoring, ranking, discipline, or compliance metrics
- reviewers and admins may not see raw identity values unless a future identity policy explicitly approves it
- reviewers and admins may not export audit data unless a future policy explicitly permits it
- review notes are not audit content by default
- no reviewer/admin audit workflow exists in this phase
AI-use audit boundaries
- AI-use audit events are future policy checks only
- AI-use audit events must not contain real submission content unless separately approved
- AI-use audit events must not store prompts containing sensitive community content
- AI-generated staff decisions remain prohibited
- OpenAI processing for real submissions is not active in this phase
Required Gates Before Implementation
- Cloudflare Access boundary approved
- identity policy approved
- pseudonymous actor policy approved
- account role mapping policy approved
- draft content policy approved
- staff review procedure approved
- Morning Sheet visibility policy approved
- retention policy approved
- deletion policy approved
- audit policy approved
- audit visibility policy approved
- escalation policy approved
- AI-use policy resolved
- D1 schema reviewed
- privacy approval complete
- rollback plan approved
- small pilot approved
What Remains Blocked
- live audit logging
- audit write endpoints
- audit tables
- active migrations
- executable SQL files
- database writes
- live retention jobs
- deletion jobs
- delete buttons
- restore buttons
- archive controls
- save buttons
- staff decision records
- live draft storage
- live review storage
- Morning Sheet live placement
- live pull-up forms
- live push-up forms
- input fields
- textareas
- submit/save/delete/archive/restore controls
- draft collection
- draft storage
- live submissions
- submission collection
- staff approval/rejection
- staff decisions
- app-level login
- account creation
- password fields
- email capture
- real user names
- real resident names
- real staff names
- real emails
- Cloudflare Access email display
- Cloudflare Access name display
- Cloudflare Access group display
- Cloudflare Access JWT display
- Cloudflare Access token display
- Cloudflare Access header display
- Cloudflare Access claim storage
- actor records
- actor storage
- account records
- account storage
- identity mapping
- role assignment
- live role assignment
- resident profiles
- staff profiles
- user admin CRUD
- write endpoints
- D1 account/user/actor/submission/draft/review/morning-sheet/audit tables
- attendance tracking
- participation tracking
- participation analytics
- scoring, ranking, discipline points, or compliance metrics
- billing, lead capture, CRM, Stripe, or sales forms
- AI for real submissions
- sensitive community content storage
Recommended Next Phase
Phase 8.10 - Live Draft Pilot Readiness Review
After audit logging policy is planned, the next safe step is reviewing whether the full account, actor, role, draft, staff review, visibility, retention, deletion, audit, AI-use, privacy, and rollback gates are ready for a very small live draft pilot.
Boundaries: no live audit logs in Phase 8.9; no audit tables; no draft storage; no live submissions; no staff decisions; no Morning Sheet placement; no retention jobs; no deletion jobs; no database writes; no active migrations; no tracking; no analytics; no scoring.
recommended-next