Renata protected audit logging planning

Audit Logging Policy Planning

Protected, read-only planning for future audit metadata before live writes, storage, jobs, or workflow controls exist.

This is a protected, read-only audit logging policy planning page. It does not create audit logs, write events, store drafts, create staff decisions, run retention jobs, or write data.

Purpose

This page defines future audit logging policy before pull-up/push-up draft storage, staff review records, Morning Sheet visibility, retention/deletion jobs, or account/actor mapping storage exists.

It is planning-only. It creates no live audit logs, audit tables, audit write endpoints, draft storage, staff decisions, retention jobs, deletion jobs, write endpoints, tables, migrations, or stored community content.

Current Storage/Audit Boundary

Product

Renata

The Sixth Sense at 6th Street

Audit logging

false

not implemented

Draft storage

false

not implemented

Writes

false

not implemented

Audit logging policy is planning-only; no audit logs, draft storage, review records, staff decisions, Morning Sheet placements, retention jobs, deletion jobs, tables, migrations, or writes exist.

Why Audit Policy Comes Before Live Writes

Future workflow storage needs a strict audit policy before any live write path exists. Audit metadata must support accountability without becoming surveillance, resident scoring, staff surveillance, or a hidden copy of deleted sensitive content.

No audit event writer, audit table, audit viewer, storage job, retention job, deletion job, active migration, or executable SQL file is added.

Audit Logging Principles

  • Audit logging exists to support accountability for system actions, not surveillance of residents.
  • Audit logs must be minimal.
  • Audit logs must not contain draft bodies unless a future policy explicitly approves a narrowly scoped exception.
  • Audit logs must not contain real names, emails, Cloudflare claims, JWTs, tokens, or raw identity headers.
  • Audit logs must not become attendance tracking.
  • Audit logs must not become participation tracking.
  • Audit logs must not become participation analytics.
  • Audit logs must not become scoring, ranking, discipline, compliance, or resident performance tracking.
  • Audit logs should record event type, pseudonymous actor ref if approved, timestamp, workflow scope, and policy reason where necessary.
  • Audit logs must be separated from sensitive draft content where possible.
  • Audit logging must be approved before live writes, staff review, retention/deletion jobs, or Morning Sheet placement exist.

Future Audit Event Categories

Category Purpose Status Active Sensitivity Allowed metadata Prohibited content
access-boundary-events future boolean access-boundary checks only planning-only false boundary-metadata-only event_type, community_id, workflow_scope, created_at, reason_code identity claim values, email, name, group claim, JWT, token, raw Access claims
actor-reference-events future actor ref creation/status events planning-only false pseudonymous-reference-metadata event_id, event_type, community_id, actor_ref, status_from, status_to, created_at, reason_code real identity, email, name, initials, resident profile details, staff profile details
role-mapping-events future role mapping changes planning-only false configuration-metadata event_id, event_type, community_id, workflow_scope, actor_ref, policy_ref, status_from, status_to, created_at live role assignment records, Cloudflare claims, email, name, attendance data, participation data
draft-lifecycle-events future draft status changes planning-only false draft-metadata-without-content event_id, event_type, community_id, workflow_scope, actor_ref, subject_actor_ref, draft_ref, status_from, status_to, created_at, retention_category draft body content by default, private feedback content by default, real names, emails, sensitive disclosures
staff-review-events future review lane/status changes planning-only false review-metadata-without-notes event_id, event_type, community_id, workflow_scope, reviewer_actor_ref, draft_ref, status_from, status_to, reason_code, created_at staff review notes by default, clinical interpretation, resident scoring, discipline points, compliance metrics
morning-sheet-visibility-events future visibility eligibility changes planning-only false visibility-metadata-only event_id, event_type, community_id, workflow_scope, draft_ref, status_from, status_to, policy_ref, created_at automatic placement, draft body content, public reading text, real identity, ranking data
retention-deletion-events future archive/delete/restore events planning-only false retention-deletion-metadata event_id, event_type, community_id, workflow_scope, draft_ref, retention_category, deletion_marker, reason_code, created_at content copying into audit logs, deleted sensitive content, private feedback content, raw identity headers
policy-configuration-events future configuration changes planning-only false config-metadata-only event_id, event_type, community_id, workflow_scope, policy_ref, status_from, status_to, reason_code, created_at resident data, staff profile details, submission content, tracking metrics, scoring data
ai-use-events future AI-use policy events planning-only false policy-check-metadata-only event_id, event_type, community_id, workflow_scope, policy_ref, reason_code, created_at real submission content unless separately approved, draft body content by default, private feedback content, OpenAI prompts containing sensitive content

Planned Audit Event Types

Event type Status Implemented Active behavior Active storage
access_boundary_checked future-only false false false
actor_ref_created future-only false false false
actor_ref_archived future-only false false false
role_mapping_planned future-only false false false
role_mapping_revoked future-only false false false
draft_created future-only false false false
draft_status_changed future-only false false false
draft_archived future-only false false false
draft_deleted future-only false false false
review_lane_changed future-only false false false
review_escalated future-only false false false
morning_sheet_visibility_marked future-only false false false
morning_sheet_visibility_blocked future-only false false false
retention_category_set future-only false false false
deletion_requested future-only false false false
deletion_completed future-only false false false
policy_config_changed future-only false false false
ai_use_policy_checked future-only false false false

Allowed Audit Metadata

Field Status Active Rule
event_id planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
event_type planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
community_id planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
workflow_scope planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
actor_ref planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
subject_actor_ref planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
reviewer_actor_ref planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
draft_ref planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
policy_ref planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
status_from planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
status_to planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
reason_code planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
created_at planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
retention_category planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.
deletion_marker planning-only false Planning-only metadata. Actor refs are conceptual until actor storage is approved; draft refs are conceptual until draft storage is approved; no table is active and no audit event is written.

Prohibited Audit Content

real namesemailsphone numbersaddressesroom numberscase numberslegal identifiersmedical identifiersinsurance identifiersCloudflare identity headersJWTstokensgroup claimsraw Access claimsresident profile detailsstaff profile detailsdraft body content by defaultprivate feedback content by defaultstaff review notes by defaultdiagnosis detailsmedication detailslegal case detailstrauma detailssubstance-use disclosuresattendance dataparticipation dataparticipation analyticsscoring dataranking datadiscipline pointscompliance metricsresident performance metrics

Audit Relationship To Retention/Deletion

Minimization

  • record the smallest useful event metadata
  • separate audit metadata from sensitive draft content where possible
  • prefer reason codes over free-text notes
  • avoid storing content copies in audit records
  • avoid storing identity values or Cloudflare Access claims
  • avoid audit fields that can become attendance, participation, scoring, compliance, or resident performance tracking
  • keep audit visibility limited until audit visibility policy is approved

Retention relationship

  • deleting draft content does not automatically mean deleting all audit metadata
  • audit metadata must be minimal and non-sensitive
  • audit metadata must not preserve deleted sensitive content
  • deleted-record markers may exist only under approved policy
  • audit log retention must be shorter or minimal where possible unless policy requires otherwise

Deletion relationship

  • permanent deletion rules require privacy/legal/staff review
  • rollback/restore events require approved policy
  • audit logs must not be used to reconstruct sensitive deleted drafts
  • deletion events must not copy draft body, private feedback, staff notes, or raw identity values into audit metadata
  • deleted-record markers are planning-only and inactive until deletion and audit policies are approved

Audit Visibility And Reviewer/Admin Boundaries

Audit visibility

  • audit visibility policy must be approved before any audit viewer exists
  • audit records must not expose real identity values or Cloudflare Access claims
  • audit records must not expose draft body content by default
  • audit visibility must not become staff surveillance or resident performance review
  • no audit UI, export, endpoint, or log viewer exists in this phase

Reviewer/admin boundaries

  • reviewers and admins may not use audit metadata for attendance, participation, scoring, ranking, discipline, or compliance metrics
  • reviewers and admins may not see raw identity values unless a future identity policy explicitly approves it
  • reviewers and admins may not export audit data unless a future policy explicitly permits it
  • review notes are not audit content by default
  • no reviewer/admin audit workflow exists in this phase

AI-use audit boundaries

  • AI-use audit events are future policy checks only
  • AI-use audit events must not contain real submission content unless separately approved
  • AI-use audit events must not store prompts containing sensitive community content
  • AI-generated staff decisions remain prohibited
  • OpenAI processing for real submissions is not active in this phase

Required Gates Before Implementation

  • Cloudflare Access boundary approved
  • identity policy approved
  • pseudonymous actor policy approved
  • account role mapping policy approved
  • draft content policy approved
  • staff review procedure approved
  • Morning Sheet visibility policy approved
  • retention policy approved
  • deletion policy approved
  • audit policy approved
  • audit visibility policy approved
  • escalation policy approved
  • AI-use policy resolved
  • D1 schema reviewed
  • privacy approval complete
  • rollback plan approved
  • small pilot approved

What Remains Blocked

  • live audit logging
  • audit write endpoints
  • audit tables
  • active migrations
  • executable SQL files
  • database writes
  • live retention jobs
  • deletion jobs
  • delete buttons
  • restore buttons
  • archive controls
  • save buttons
  • staff decision records
  • live draft storage
  • live review storage
  • Morning Sheet live placement
  • live pull-up forms
  • live push-up forms
  • input fields
  • textareas
  • submit/save/delete/archive/restore controls
  • draft collection
  • draft storage
  • live submissions
  • submission collection
  • staff approval/rejection
  • staff decisions
  • app-level login
  • account creation
  • password fields
  • email capture
  • real user names
  • real resident names
  • real staff names
  • real emails
  • Cloudflare Access email display
  • Cloudflare Access name display
  • Cloudflare Access group display
  • Cloudflare Access JWT display
  • Cloudflare Access token display
  • Cloudflare Access header display
  • Cloudflare Access claim storage
  • actor records
  • actor storage
  • account records
  • account storage
  • identity mapping
  • role assignment
  • live role assignment
  • resident profiles
  • staff profiles
  • user admin CRUD
  • write endpoints
  • D1 account/user/actor/submission/draft/review/morning-sheet/audit tables
  • attendance tracking
  • participation tracking
  • participation analytics
  • scoring, ranking, discipline points, or compliance metrics
  • billing, lead capture, CRM, Stripe, or sales forms
  • AI for real submissions
  • sensitive community content storage

Recommended Next Phase

Phase 8.10 - Live Draft Pilot Readiness Review

After audit logging policy is planned, the next safe step is reviewing whether the full account, actor, role, draft, staff review, visibility, retention, deletion, audit, AI-use, privacy, and rollback gates are ready for a very small live draft pilot.

Boundaries: no live audit logs in Phase 8.9; no audit tables; no draft storage; no live submissions; no staff decisions; no Morning Sheet placement; no retention jobs; no deletion jobs; no database writes; no active migrations; no tracking; no analytics; no scoring.

recommended-next