Audit and evidence model
Use this model to distinguish operational logs from the structured evidence expected for a material action.
Scope
ClearPoint separates logs from audit evidence. Logs help operators diagnose runtime behavior. Audit evidence is structured, tenant-scoped where applicable, and designed to answer who or what acted, what changed, which policy context was used, and which evidence hash supports the record.
Trust boundary
Public evidence summaries stop before raw restricted values, regulated payloads, customer-specific evidence packets, and private artifacts. Those records remain in the authenticated or NDA-backed workflow approved for their audience.
Control objective
The audit canon treats actions as material when they change or expose identity, access, runtime behavior, policy, money, customer data, certification state, evidence, deployment, security posture, or public trust claims. Material actions must produce an evidence record before the action is considered complete, unless the source canon classifies the action as non-material and recoverable.
Data handled
Evidence records are expected to carry stable identifiers, actor context, resource context, decision state, correlation identifiers, data classification, payload hash, signature metadata, and redaction profile.
Evidence produced
The expected output is a structured evidence record that identifies the action, subject, decision context, and integrity metadata needed for bounded review.
Limitations
An evidence record supports only the action, state, source, and time it represents. It does not turn general logs into audit evidence or establish a broader safety or compliance conclusion.
Responsibilities
Security reviewers can use this model to understand how ClearPoint expects release, configuration, access, evidence export, and trust-claim changes to be reviewed. The owner of a material action remains responsible for producing the required record and keeping sensitive values out of its public summary.
Source
The authoritative model is the ClearPoint audit-evidence canon identified by this page's source metadata. This page is a public technical projection of that model.
Next steps
Read the security control model for the public control map or the data handling model for classification and retention boundaries.
Related documentation
See also
Terms used on this page
Report a problem with this page
- Doc ID
cpl.docs.security.audit_evidence- Source
cpl-ops:docs/standards/platform-pack/CPL-AUDIT-EVIDENCE-CANONICAL.md#1- Updated