Skip to main content

5 docs tagged with "soc2"

View all tags

ADR-021: Delegated-Agent Audit Log Storage

Pick a persistent store for delegated_agent audit log entries. Recommend Grafana Cloud Loki (already adopted by ADR-019, free at pilot scale) for general-purpose audit retention, with a small Mongo audit_logs collection reserved only for the customer-facing 'who did what' query surface once a tenant asks for one.

Entity Type Classification — CISO

Round 5 CISO analysis on what entity type Business Rules, Script Includes, REST Messages, OAuth Profiles, Flow Designer Flows, and Scheduled Jobs should actually be in the SecurityV0 data model

OAA Mapping Analysis — CISO

Round 4 CISO analysis evaluating how OAA (Open Authorization API) concepts map to SecurityV0's automation chain modeling