Guide

Logs vs evidence bundles

Archaeology vs replay.

Audit logs record events. Evidence bundles bind action, policy, identity, risk, and approval into a replayable authority decision auditors can trust.

Why logs fail auditors

Log pipelines lose correlation. Policy versions change. Approvals in chat or email are not bound to execution. Reconstructing 'who authorized this refund?' becomes archaeology.

What evidence bundles contain

Evidence is tamper-evident and hash-bound so replay years later proves what was evaluated.

  • Proposed action and payload hash
  • Policy snapshot in force at decision time
  • Actor identity and continuity context
  • Risk advisory signals
  • Approval record when APPROVAL_REQUIRED
  • Decision outcome: ALLOW, DENY, or APPROVAL_REQUIRED

Frequently asked questions

Do evidence bundles replace SIEM?

No. SIEM aggregates signals. Evidence bundles prove a specific authority decision at execution time.

Related

Next step

Map your workflows

See where action authority fits in your stack — no credentials required.