Start with critical operations and required evidence
For each operation, verify path, scope, fields, retention, integrity, reversibility, external effects, tests, and owner.
Short answer
Action, access, undo and redo foundations with deployment-specific audit coverage
Current Open Mercato provides separate action and selected read-access records plus handler-defined undo and explicit redo. A deployment must still prove command and read coverage, delivery, retention, integrity, permissions, external-effect handling, reconciliation and compliance fitness.
- Reviewed
- 2026-07-14
- Revision
- 01911d00e28f44cf484d0b1d04860dcfef5370bf (v0.6.5-1202-g01911d00e)
- Latest tag and package
- v0.6.5 · 0.6.5 · current redo and access batching are post-tag observations
This editorial guide supports audit planning. Legal advice, formal audits, compliance opinions, certification and deployment evidence must come from the responsible professionals and owners.
Fourteen terms that must stay distinct
1. action log
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
2. access log
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
3. authentication and authorization evidence
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
4. domain event or workflow history
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
5. application and infrastructure logs
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
6. external acknowledgement
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
7. evidence chain
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
8. coverage
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
9. undo
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
10. redo
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
11. retention
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
12. integrity and tamper evidence
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
13. audit export
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
14. revision boundary
Define its scope, producer, consumer, retention, integrity, visibility and excluded meanings before relying on it.
Evidence chain
- 1
identity and request
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 2
authentication and session
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 3
authorization and scope
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 4
command or read
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 5
database outcome
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 6
action or access record
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 7
event, job, index or cache
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 8
external request and acknowledgement
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 9
reconciliation
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
- 10
business outcome
Record the current mechanism, possible gap, minimum acceptance proof, accountable role and whether the stage is native, configurable, custom, integration-dependent or deployment-specific.
Log and evidence type matrix
1. action
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
2. access
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
3. authentication/session
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
4. authorization decision/denial
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
5. application error
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
6. security event
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
7. domain event
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
8. workflow execution
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
9. queue/job
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
10. scheduler
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
11. integration request/response
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
12. webhook delivery
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
13. external provider acknowledgement
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
14. database/admin
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
15. infrastructure
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
16. backup/restore
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
17. business reconciliation
State purpose, actor/resource/scope, current evidence, excluded meanings, sensitivity, retention and integrity owners, query/export path, and project decision.
Action and access coverage boundaries
Action rows can carry tenant, organization, actor, command, label, action/resource types, related resources, state, token, input, snapshots, changes, context, source and timestamps. Field population varies by command. A handler requires only id and execute. Rows can be absent when metadata or the audit service is missing, skipLog or a no-op/deduplicated result applies, audit-resource recursion is prevented, a direct/custom write bypasses the bus, or the command never uses it. Build a risk-grouped operation inventory. A raw-search percentage is insufficient.
Standard CRUD paths log one row per unique returned resource id with inferred access type, field names, result count, query-key names and path where available. Empty results produce no per-resource row. Cached branches are instrumented. Custom APIs, direct ORM, search, reports, dashboards, exports, attachments, portal, AI, background jobs, integrations, support tools and denied attempts require explicit review. Normal writes are batched and tracked without awaiting the result, and fail open unless blocking mode is selected and tested.
- standard CRUD
- cached results
- custom API routes
- direct ORM
- search
- reports
- dashboards
- exports
- attachments
- portal
- AI tools
- background jobs
- integrations
- administrator/support tools
- denied attempts
Retention, encryption and integrity
Access records default to seven days for auth.user/auth.role and eight hours for other resources through AUDIT_LOGS_CORE_RETENTION_DAYS and AUDIT_LOGS_NON_CORE_RETENTION_HOURS. Cleanup hard-deletes after successful writes and is throttled per process by AUDIT_LOGS_ROTATE_INTERVAL_MS, default 60 seconds. Cleanup runs opportunistically. It does not provide exact scheduling, an archive, a legal hold or action retention. No general action-log archive/retention worker was established. Selected payload, snapshot, change, context, resource and field data appear in configurable encryption maps. Review query columns and decrypted APIs.
1. ordinary mutable row
Potential deployment control; verify actual implementation and evidence.
2. restricted database access
Potential deployment control; verify actual implementation and evidence.
3. monitored administration
Potential deployment control; verify actual implementation and evidence.
4. append-only application policy
Potential deployment control; verify actual implementation and evidence.
5. separate archive
Not established by reviewed audit source.
6. tamper-evident hashing or signing
Not established by reviewed audit source.
7. trusted timestamp
Not established by reviewed audit source.
8. WORM or regulated repository
Not established by reviewed audit source.
Reviewed source does not show cryptographic chaining, signing, trusted timestamps, WORM storage, non-repudiation, legal admissibility or protection from every privileged operator.
Permissions and export
view_self starts list access; view_tenant can widen actor visibility inside the authenticated tenant and allowed organization scope. The access view still defaults to the caller unless another actor is queried. undo_self, undo_tenant, redo_self and redo_tenant are separate. Employees default to view_self and undo_self; redo_self is excluded from their defaults. Apply least privilege, separation of duties, periodic review, break-glass and revocation.
The action CSV is action-only, filtered, has a limit 1000 records, and flattens change rows into When, User, Action, Field, Old Value, New Value and Source. It covers a limited evidence set and excludes access records. Record exporter, scope, file classification, destination, encryption, expiry, deletion, disclosure, completeness and whether the export itself is evidenced.
Operation-specific reversibility
1. not evidenced
Assign per operation with source and acceptance evidence. Never infer it from a module name.
2. action evidenced; reversal unavailable
Assign per operation with source and acceptance evidence. Never infer it from a module name.
3. locally undoable
Assign per operation with source and acceptance evidence. Never infer it from a module name.
4. locally redoable
Assign per operation with source and acceptance evidence. Never infer it from a module name.
5. compensated through a new business action
Assign per operation with source and acceptance evidence. Never infer it from a module name.
6. external reversal supported
Assign per operation with source and acceptance evidence. Never infer it from a module name.
7. manual recovery and reconciliation required
Assign per operation with source and acceptance evidence. Never infer it from a module name.
Undo requires a handler, token, done state, actor/tenant/organization scope and latest eligible resource or actor action. A compare-and-set done to undoing blocks double execution; failure releases the claim; success consumes the token and writes an inverse trace. Redo is an explicit current-source route with separate permission: it uses stored input or handler restoration for the latest undone action, marks the source redone and may create a fresh action and token. Current constraints can cause collision; same-id restoration is handler-specific. The 10-second banner controls UI visibility. It does not determine eligibility, retention, rollback or recovery.
Transaction and failure matrix
1. business mutation
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
2. action persistence
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
3. access persistence
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
4. cache invalidation
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
5. index update
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
6. event emission
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
7. queue delivery
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
8. external call
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
9. callback
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
10. reconciliation
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
11. undo and redo
Record ordering, established or unknown atomicity, retry and idempotency, partial-success state, monitoring, compensating action, reconciliation and owner. Unknown remains unknown.
Local undo cannot retract a payment, shipment, email, webhook, file, notification, consumed event or third-party state unless that integration implements and verifies a reversal.
Three synthetic examples
Hypothetical only
Synthetic customer-record correction
Load the structural coverage row to challenge evidence, reversibility, retention, integrity, external effects and ownership.
Hypothetical only
Synthetic CSV or batch update
Load the structural coverage row to challenge evidence, reversibility, retention, integrity, external effects and ownership.
Hypothetical only
Synthetic external-effect action
Load the structural coverage row to challenge evidence, reversibility, retention, integrity, external effects and ownership.
Local planning tool
Audit coverage register
Use coverage status to plan the evidence you still need. Formal audit grades, certificates and compliance scores come from the responsible auditors or assessors.
Do not enter real data: Do not enter production values, personal data, secrets, tokens, payloads, raw log rows, sensitive URLs or real identifiers. Store structural labels and non-sensitive evidence references only.
Privacy: The page does not send worksheet content, put it in the URL, or store it in cookies.
Acceptance pack
1. expected action row
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
2. missing or skip path
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
3. read row
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
4. empty or denied read
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
5. self and tenant actor scope
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
6. cross-tenant denial
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
7. cross-organization denial
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
8. sensitive-field minimization
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
9. encryption on and off
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
10. access-write failure
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
11. concurrency
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
12. action-log failure after mutation
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
13. cache, index or event failure
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
14. undo success
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
15. undo failure
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
16. double undo submit
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
17. latest-action ordering
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
18. redo success
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
19. redo collision
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
20. redo stale input
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
21. export scope and cap
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
22. retention cleanup
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
23. retention with no new write
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
24. archive and restore
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
25. privileged tamper attempt
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
26. external partial success
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
27. upgrade and projection backfill
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
28. custom route coverage
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
29. malformed metadata
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
30. provider callback duplication
State setup, actor, operation, expected business result and evidence, prohibited effect, induced failure, cleanup, owner and pass criterion.
Stop or defer
- unknown coverage for a critical operation.
- no accountable owner.
- access evidence shorter than investigation need.
- sensitive payload overcollection.
- untested privileged access.
- missing archive or legal-hold need.
- unproven cross-scope restrictions.
- no external reconciliation.
- ambiguous undo side effects.
- missing restore evidence.
- required action/log atomicity is unproven.
- required WORM or signing is not implemented.
Method and documentation drift
Evidence was refreshed at the exact revision across audit entities, services, ACL, setup, encryption, action/access APIs, current undo/redo routes and tests, command bus, CRUD access helper, UI and user guide. The reviewed guide text still implies narrower undo support and manual redo; current source contains explicit redo UI, route, permissions, states and tests. The redo behavior described here comes from current source. The v0.6.5 tag is described separately.