Audit Logs
The immutable record of every access, change, and policy decision across the platform — what makes every other control provable, not just claimed.
High-Level Design
Audit Logs are the evidence layer behind every governance control.
💼 Business Context
- Compliance frameworks (SOC 2, GDPR, ISO 27001) require provable audit trails, not just policy documents claiming controls exist
- Turns "did anyone access this customer's data inappropriately" from an unanswerable question into a queryable log
- Owned by Security / Compliance
🔌 Technical Overview
Every governance-relevant action — consent decisions, access-control evaluations, schema governance rejections, lifecycle deletions — writes an immutable, append-only record to a dedicated audit log store (Azure Data Lake Storage Gen2, write-once configuration, separate from operational tables). Audit records are structured and queryable, letting Compliance run investigations without needing to grep application logs.
Logged Events
💾 Audit Log Entry
{
"timestamp": "2026-08-01T12:00:03Z",
"actor": "agt_302",
"action": "query",
"resource": "curated.customer_profile",
"decision": "allow",
"policy_ref": "abac-region-rule-4"
}
🔗 Integration Points
- Azure Data Lake Storage Gen2 (write-once configuration) — immutable audit log storage
- Consent Enforcement, Access Control, Governance Rules — all write audit entries
- Compliance reporting tools — query the audit log store
- Azure Monitor — operational alerting on suspicious audit patterns
🧰 Services Consumed
- Owning microservice —
Cxos.Foundation.Api(see the Full Application Service Map) - Database — ADLS Gen2 (Iceberg) + Azure Database for PostgreSQL (policy/retention state)
⚠️ Non-Functional Considerations
- Scale: audit logging is append-only and write-optimized, sized for governance-relevant decision volume, not raw event volume
- Latency: audit writes are asynchronous relative to the action they log, so they never slow down the primary operation
- Reliability: write-once storage configuration prevents tampering, including by administrators
- Security/Privacy: access to the audit log itself is tightly restricted — auditing the auditors is a standard security requirement
🎯 Enterprise Example
A regulator asks for proof that a specific customer's marketing-consent withdrawal was honored. Compliance queries the audit log and produces a complete, tamper-proof record of the consent change and every subsequent access decision — turning a multi-week manual investigation into a same-day query.