What the record contains
- The candidate that was proposed and the boundary it reached.
- The modules that ran, their findings and supporting evidence references.
- The policy and authority versions in force at decision time.
- The final Permit, Observe or Abstain disposition with its reason.
Refusals are first-class decisions
In systems that can refuse, a refusal is not merely an error. Recording it with the same weight as an approval makes safety behavior visible, lets teams measure over-refusal, and gives reviewers evidence that controls acted before a commitment.
Append-only changes preserve context
A correction references the original record instead of replacing it. Hash-linked entries make alteration detectable, while configuration versions allow a reviewer to reconstruct the decision as it was made rather than applying today's rules to yesterday's event.
Who uses it
- Product teams investigate behavior without reconstructing it from unrelated logs.
- Compliance teams answer review questions from the customer's own deployment.
- Engineering teams compare module drift and decision populations over time.
- Leaders show governed decisions instead of presenting raw event volume as assurance.