Start with critical operations and required evidence

For each operation, verify path, scope, fields, retention, integrity, reversibility, external effects, tests, and owner.

Short answer

Action, access, undo and redo foundations with deployment-specific audit coverage

Current Open Mercato provides separate action and selected read-access records plus handler-defined undo and explicit redo. A deployment must still prove command and read coverage, delivery, retention, integrity, permissions, external-effect handling, reconciliation and compliance fitness.

Reviewed
2026-07-14
Revision
01911d00e28f44cf484d0b1d04860dcfef5370bf (v0.6.5-1202-g01911d00e)
Latest tag and package
v0.6.5 · 0.6.5 · current redo and access batching are post-tag observations

This editorial guide supports audit planning. Legal advice, formal audits, compliance opinions, certification and deployment evidence must come from the responsible professionals and owners.

Fourteen terms that must stay distinct

1. action log

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

2. access log

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

3. authentication and authorization evidence

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

4. domain event or workflow history

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

5. application and infrastructure logs

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

6. external acknowledgement

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

7. evidence chain

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

8. coverage

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

9. undo

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

10. redo

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

11. retention

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

12. integrity and tamper evidence

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

13. audit export

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

14. revision boundary

Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.

Evidence chain

  1. 1

    identity and request

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  2. 2

    authentication and session

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  3. 3

    authorization and scope

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  4. 4

    command or read

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  5. 5

    database outcome

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  6. 6

    action or access record

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  7. 7

    event, job, index or cache

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  8. 8

    external request and acknowledgement

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  9. 9

    reconciliation

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

  10. 10

    business outcome

    Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.

Log and evidence type matrix

1. action

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

2. access

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

3. authentication/session

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

4. authorization decision/denial

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

5. application error

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

6. security event

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

7. domain event

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

8. workflow execution

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

9. queue/job

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

10. scheduler

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

11. integration request/response

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

12. webhook delivery

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

13. external provider acknowledgement

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

14. database/admin

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

15. infrastructure

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

16. backup/restore

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

17. business reconciliation

State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.

Action and access coverage boundaries

Action rows can carry tenant, organization, actor, command, label, action/resource types, related resources, state, token, input, snapshots, changes, context, source and timestamps. Field population varies by command. A handler requires only id and execute. Rows can be absent when metadata or the audit service is missing, skipLog or a no-op/deduplicated result applies, audit-resource recursion is prevented, a direct/custom write bypasses the bus, or the command never uses it. Build a risk-grouped operation inventory. A raw-search percentage is insufficient.

Standard CRUD paths log one row per unique returned resource id with inferred access type, field names, result count, query-key names and path where available. Empty results produce no per-resource row. Cached branches are instrumented. Custom APIs, direct ORM, search, reports, dashboards, exports, attachments, portal, AI, background jobs, integrations, support tools and denied attempts require explicit review. Normal writes are batched and tracked without awaiting the result, and fail open unless blocking mode is selected and tested.

  • standard CRUD
  • cached results
  • custom API routes
  • direct ORM
  • search
  • reports
  • dashboards
  • exports
  • attachments
  • portal
  • AI tools
  • background jobs
  • integrations
  • administrator/support tools
  • denied attempts

Retention, encryption and integrity

Access records default to seven days for auth.user/auth.role and eight hours for other resources through AUDIT_LOGS_CORE_RETENTION_DAYS and AUDIT_LOGS_NON_CORE_RETENTION_HOURS. Cleanup hard-deletes after successful writes and is throttled per process by AUDIT_LOGS_ROTATE_INTERVAL_MS, default 60 seconds. Cleanup runs opportunistically. It does not provide exact scheduling, an archive, a legal hold or action retention. No general action-log archive/retention worker was established. Selected payload, snapshot, change, context, resource and field data appear in configurable encryption maps. Review query columns and decrypted APIs.

1. ordinary mutable row

Potential deployment control; verify actual implementation and evidence.

2. restricted database access

Potential deployment control; verify actual implementation and evidence.

3. monitored administration

Potential deployment control; verify actual implementation and evidence.

4. append-only application policy

Potential deployment control; verify actual implementation and evidence.

5. separate archive

Not established by reviewed audit source.

6. tamper-evident hashing or signing

Not established by reviewed audit source.

7. trusted timestamp

Not established by reviewed audit source.

8. WORM or regulated repository

Not established by reviewed audit source.

Reviewed source does not show cryptographic chaining, signing, trusted timestamps, WORM storage, non-repudiation, legal admissibility or protection from every privileged operator.

Permissions and export

view_self starts list access; view_tenant can widen actor visibility inside the authenticated tenant and allowed organization scope. The access view still defaults to the caller unless another actor is queried. undo_self, undo_tenant, redo_self and redo_tenant are separate. Employees default to view_self and undo_self; redo_self is excluded from their defaults. Apply least privilege, separation of duties, periodic review, break-glass and revocation.

The action CSV is action-only, filtered, has a limit 1000 records, and flattens change rows into When, User, Action, Field, Old Value, New Value and Source. It covers a limited evidence set and excludes access records. Record exporter, scope, file classification, destination, encryption, expiry, deletion, disclosure, completeness and whether the export itself is evidenced.

Operation-specific reversibility

1. not evidenced

Assign per operation with source and acceptance evidence. Never infer it from a module name.

2. action evidenced; reversal unavailable

Assign per operation with source and acceptance evidence. Never infer it from a module name.

3. locally undoable

Assign per operation with source and acceptance evidence. Never infer it from a module name.

4. locally redoable

Assign per operation with source and acceptance evidence. Never infer it from a module name.

5. compensated through a new business action

Assign per operation with source and acceptance evidence. Never infer it from a module name.

6. external reversal supported

Assign per operation with source and acceptance evidence. Never infer it from a module name.

7. manual recovery and reconciliation required

Assign per operation with source and acceptance evidence. Never infer it from a module name.

Undo requires a handler, token, done state, actor/tenant/organization scope and latest eligible resource or actor action. A compare-and-set done to undoing blocks double execution; failure releases the claim; success consumes the token and writes an inverse trace. Redo is an explicit current-source route with separate permission: it uses stored input or handler restoration for the latest undone action, marks the source redone and may create a fresh action and token. Current constraints can cause collision; same-id restoration is handler-specific. The 10-second banner controls UI visibility. It does not determine eligibility, retention, rollback or recovery.

Transaction and failure matrix

1. business mutation

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

2. action persistence

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

3. access persistence

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

4. cache invalidation

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

5. index update

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

6. event emission

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

7. queue delivery

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

8. external call

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

9. callback

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

10. reconciliation

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

11. undo and redo

Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.

Local undo cannot retract a payment, shipment, email, webhook, file, notification, consumed event or third-party state unless that integration implements and verifies a reversal.

Three synthetic examples

Hypothetical only

Synthetic customer-record correction

Load the structural coverage row to challenge evidence, reversibility, retention, integrity, external effects and ownership.

Hypothetical only

Synthetic CSV or batch update

Load the structural coverage row to challenge evidence, reversibility, retention, integrity, external effects and ownership.

Hypothetical only

Synthetic external-effect action

Load the structural coverage row to challenge evidence, reversibility, retention, integrity, external effects and ownership.

Local planning tool

Audit coverage register

Use coverage status to plan the evidence you still need. Formal audit grades, certificates and compliance scores come from the responsible auditors or assessors.

Do not enter real data: Do not enter production values, personal data, secrets, tokens, payloads, raw log rows, sensitive URLs or real identifiers. Store structural labels and non-sensitive evidence references only.

Privacy: The page does not send worksheet content, put it in the URL, or store it in cookies.

Required-field progress: Not started (0/17). This count tracks field completion. It does not score fit or determine readiness.
Planning row 1

Acceptance pack

1. expected action row

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

2. missing or skip path

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

3. read row

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

4. empty or denied read

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

5. self and tenant actor scope

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

6. cross-tenant denial

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

7. cross-organization denial

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

8. sensitive-field minimization

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

9. encryption on and off

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

10. access-write failure

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

11. concurrency

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

12. action-log failure after mutation

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

13. cache, index or event failure

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

14. undo success

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

15. undo failure

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

16. double undo submit

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

17. latest-action ordering

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

18. redo success

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

19. redo collision

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

20. redo stale input

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

21. export scope and cap

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

22. retention cleanup

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

23. retention with no new write

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

24. archive and restore

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

25. privileged tamper attempt

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

26. external partial success

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

27. upgrade and projection backfill

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

28. custom route coverage

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

29. malformed metadata

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

30. provider callback duplication

State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.

Stop or defer

  • unknown coverage for a critical operation.
  • no accountable owner.
  • access evidence shorter than investigation need.
  • sensitive payload overcollection.
  • untested privileged access.
  • missing archive or legal-hold need.
  • unproven cross-scope restrictions.
  • no external reconciliation.
  • ambiguous undo side effects.
  • missing restore evidence.
  • required action/log atomicity is unproven.
  • required WORM or signing is not implemented.

Method and documentation drift

Evidence was refreshed at the exact revision across audit entities, services, ACL, setup, encryption, action/access APIs, current undo/redo routes and tests, command bus, CRUD access helper, UI and user guide. The reviewed guide text still implies narrower undo support and manual redo; current source contains explicit redo UI, route, permissions, states and tests. The redo behavior described here comes from current source. The v0.6.5 tag is described separately.