Repeated authentication failure
Failures grouped by source address rather than by account, so a few attempts spread across many accounts surfaces.
that shape is critical · flat volume against one account is a warning
Entries are written once and never updated — no edits, no soft deletes. Each names the actor by id; the name lives beside the trail, so the trail still reads after the account is removed, and the name can be erased on request without touching a single sealed record.
at 2026-08-04 11:41:07 UTC
actor user 3f9c…0e21 (name shown from beside the trail)
session s-4f21… ip 10.42.6.18 agent broka-ui
privileged yes
env production policy: read-only
broker rabbitmq cluster: rmq-core-01
resource queue q.pay.us classification: confidential
action broker.queue.purge
outcome failure — blocked by environment policyA broker's own logs record the connection BROKA opened, not the person behind it — brokers have no field for one. So each connection is identified as itself on the wire, and the trail on BROKA's side is what turns that connection and moment into a named actor.
Verify any range and get a plain answer: entries checked, links verified, the first entry where the chain breaks if it does, and which ranges were pruned by retention rather than missing.
Retention always runs and keeps at most six months — 180 days, which is also the default. The window can be shortened at runtime but never switched off, with a floor your deployment sets so it cannot be quietly lowered to nothing. Pruning is deliberately hard to get wrong.
Only a forwarded copy still holds it. Forwarding to a file or an HTTP endpoint is set in the deployment environment and is in both editions. Forwarding to Kafka or RabbitMQ is Commercial: a registered connection, chosen in Settings › Security. A record that was never forwarded is still deleted at 180 days, and BROKA warns seven days before.
action audit.trail.prune
cutoff 2026-02-05T00:00:00Z
removed 182,417 records
window 180 days
outcome success — chain links marked prunedEach batch commits with its own record, so an interrupted sweep still leaves a witness. Surviving links are marked as pruned rather than broken, which keeps verification honest about the difference between deleted and altered.
Pick a date range and get a single archive built from one consistent point-in-time read, so the files in it cannot disagree with each other. It is meant to be handed to an auditor as-is.
The manifest carries a SHA-256 digest of every file, computed over the bytes actually written into the archive. Beyond those digests there is no cryptographic signing — a deliberate scope decision for a product that has to work air-gapped, and one we would rather state than blur.
The trail is swept every few minutes. Each detector is a plain rule an operator can reason about — no opaque scoring, and no claim to detect intent.
Failures grouped by source address rather than by account, so a few attempts spread across many accounts surfaces.
that shape is critical · flat volume against one account is a warning
An actor changing their own roles, team membership or environment rights.
legitimate sometimes · never uninteresting
Measured against a baseline learned per actor, not against fixed office hours.
a follow-the-sun team has no single working day
Unusual volumes of message reads in a short window, judged by volume alone — in Commercial, where reads are recorded.
no data-sensitivity taxonomy is claimed or implied