concept · securityPublicVersion current

Audit and evidence model

Use this model to distinguish operational logs from the structured evidence expected for a material action.

Scope

ClearPoint separates logs from audit evidence. Logs help operators diagnose runtime behavior. Audit evidence is structured, tenant-scoped where applicable, and designed to answer who or what acted, what changed, which policy context was used, and which evidence hash supports the record.

Trust boundary

Public evidence summaries stop before raw restricted values, regulated payloads, customer-specific evidence packets, and private artifacts. Those records remain in the authenticated or NDA-backed workflow approved for their audience.

Control objective

The audit canon treats actions as material when they change or expose identity, access, runtime behavior, policy, money, customer data, certification state, evidence, deployment, security posture, or public trust claims. Material actions must produce an evidence record before the action is considered complete, unless the source canon classifies the action as non-material and recoverable.

Data handled

Evidence records are expected to carry stable identifiers, actor context, resource context, decision state, correlation identifiers, data classification, payload hash, signature metadata, and redaction profile.

Evidence produced

The expected output is a structured evidence record that identifies the action, subject, decision context, and integrity metadata needed for bounded review.

Limitations

An evidence record supports only the action, state, source, and time it represents. It does not turn general logs into audit evidence or establish a broader safety or compliance conclusion.

Responsibilities

Security reviewers can use this model to understand how ClearPoint expects release, configuration, access, evidence export, and trust-claim changes to be reviewed. The owner of a material action remains responsible for producing the required record and keeping sensitive values out of its public summary.

Source

The authoritative model is the ClearPoint audit-evidence canon identified by this page's source metadata. This page is a public technical projection of that model.

Next steps

Read the security control model for the public control map or the data handling model for classification and retention boundaries.

Terms used on this page

Report a problem with this page

Do not include secrets or customer data.


Doc ID
cpl.docs.security.audit_evidence
Source
cpl-ops:docs/standards/platform-pack/CPL-AUDIT-EVIDENCE-CANONICAL.md#1
Updated