Observed arrival · 2026-08-25
The Audit Log Page
A five-part technical essay about designing product audit logs for the auditor who must reconstruct events long after they happened.
Field notes
The essay treats an audit trail as an application product surface rather than infrastructure exhaust. Its example schema separates occurred_at from recorded_at, preserves actor snapshots, records allowed and denied outcomes, and stores narrowed before-and-after values for changes. A shared set of 43 events links the opening schema discussion to later evidence questions, while examples cover role changes, erasure, API activity, agents, impersonation, and HTTP telemetry.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue