Unified Data Foundation → Governance & Security

Audit Logs

The immutable record of every access, change, and policy decision across the platform — what makes every other control provable, not just claimed.

High-Level Design

Audit Logs are the evidence layer behind every governance control.

Data Source
Data Sources
Every touchpoint and business system
→
Ingestion
Consent Enforcement
Every consent decision is logged here
→
Processing
Access Control (RBAC/ABAC)
Every access decision is logged here
→
Foundation
Audit Logs
Immutable, append-only log store
→
Intelligence
Compliance Reporting
The primary consumer of audit data
→
Activation
Regulatory & Internal Investigations
What audit logs ultimately support

💼 Business Context

  • Compliance frameworks (SOC 2, GDPR, ISO 27001) require provable audit trails, not just policy documents claiming controls exist
  • Turns "did anyone access this customer's data inappropriately" from an unanswerable question into a queryable log
  • Owned by Security / Compliance

🔌 Technical Overview

Every governance-relevant action — consent decisions, access-control evaluations, schema governance rejections, lifecycle deletions — writes an immutable, append-only record to a dedicated audit log store (Azure Data Lake Storage Gen2, write-once configuration, separate from operational tables). Audit records are structured and queryable, letting Compliance run investigations without needing to grep application logs.

Logged Events

Consent decisions Access-control evaluations Schema governance rejections Lifecycle deletions

💾 Audit Log Entry

{
  "timestamp": "2026-08-01T12:00:03Z",
  "actor": "agt_302",
  "action": "query",
  "resource": "curated.customer_profile",
  "decision": "allow",
  "policy_ref": "abac-region-rule-4"
}

🔗 Integration Points

  • Azure Data Lake Storage Gen2 (write-once configuration) — immutable audit log storage
  • Consent Enforcement, Access Control, Governance Rules — all write audit entries
  • Compliance reporting tools — query the audit log store
  • Azure Monitor — operational alerting on suspicious audit patterns

🧰 Services Consumed

  • Owning microservice — Cxos.Foundation.Api (see the Full Application Service Map)
  • Database — ADLS Gen2 (Iceberg) + Azure Database for PostgreSQL (policy/retention state)

⚠️ Non-Functional Considerations

  • Scale: audit logging is append-only and write-optimized, sized for governance-relevant decision volume, not raw event volume
  • Latency: audit writes are asynchronous relative to the action they log, so they never slow down the primary operation
  • Reliability: write-once storage configuration prevents tampering, including by administrators
  • Security/Privacy: access to the audit log itself is tightly restricted — auditing the auditors is a standard security requirement

🎯 Enterprise Example

A regulator asks for proof that a specific customer's marketing-consent withdrawal was honored. Compliance queries the audit log and produces a complete, tamper-proof record of the consent change and every subsequent access decision — turning a multi-week manual investigation into a same-day query.

← Back to Governance & Security