drill of 17/08/2026REQ-064AUDIT_EVENT_APPENDED

Facts⁠, not adjectives.

A guarantee without an artefact is a statement. This page cites only controls that have been executed, each tied to the piece that documents it. What has not been exercised does not appear here.

  1. 01

    Append-only audit journal

    Deleting or altering an entry of the audit journal is rejected by database-engine triggers. At the anti-test of 17 August 2026, the deletion attempt failed even as superuser — 0 deletions possible.

    Artefact: drill report b2-p2-pitr-oldest-antitest-20260817 (hospitality-lcos repository, docs/audit).

  2. 02

    Restoration rehearsed, not promised

    On 17 August 2026 the database was restored to a point in time from an encrypted off-site repository, in 114 s. The 21 tables in scope returned 21/21 fingerprints identical to the expected set, 0 mismatches. The measured scope is that of the drill: surviving server, tooling in place.

    Artefact: drill journal b2-drill-pitr-20260817221349.json (canonical digests, cardinalities, measured duration).

  3. 03

    Approvals by role matrix

    A contract’s risk level determines which roles must decide, up to external counsel and executive management for the highest levels. Ratifying an approval rule emits a journalled event (APPROVAL_RULE_RATIFIED); an approver cannot approve their own request.

    Artefact: end-to-end test suite of the approval matrix (module 35), which verifies the event and its audit-journal entry.

  4. 04

    Stable, correlated errors

    A refusal from the system carries a stable error code: the same cause yields the same code, together with a correlation identifier tying the response to its journal entry.

    Artefact: stable-error catalogue of the master specification (§51); the repository’s test suites verify the codes returned.

These proofs are dated and can be replayed. They cover the perimeter exercised at their date — no more — and each new drill replaces a statement with a measurement.