Audit
In-memory audit records and current evidence limitations.
Record and inspect local events
ProductionAuditTrailManager stores (AuditEventId, AuditEvent) entries in an in-memory vector behind an async lock. Event IDs are timestamp-based. This implementation has no cryptographic hash chain or durable backend.
use weave_compliance::audit::{AuditEvent, AuditTrailManager, ProductionAuditTrailManager};
async fn record_local_event() -> Result<(), Box<dyn std::error::Error>> {
let manager = ProductionAuditTrailManager::new();
let id = manager.record_audit_event(AuditEvent {
event_type: "example.started".into(),
actor: "local-example".into(),
target: "example-run".into(),
details: serde_json::json!({"version": 1}),
timestamp: chrono::Utc::now(),
compliance_context: None,
}).await?;
println!("{}", id.0);
Ok(())
}generate_audit_report currently sets integrity_verified to a fixed true value and uses a placeholder signature. These fields are not a verification result or signed evidence. The regulation-specific recording helpers return generated evidence IDs without appending the corresponding event to the vector.
The forgetting implementation edits matching event targets and attempts to record another event while still holding the write lock. That lock re-entry can prevent completion; do not treat this path as a verified deletion workflow. Its target-only redaction also does not remove personal data from other fields.
Source reference
Exact declarations and source provenance · Package features and manifest.