g1t/services/events/migrations/0002_audit.sql
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | -- The audit log: every action taken with a run credential, and every |
| 2 | -- change people and workspace tokens make through the API and git, with | |
| 3 | -- whether it was allowed and the rule that decided. Append-only: nothing | |
| 4 | -- updates or deletes a row except a workspace rename, which moves its | |
| 5 | -- rows to the new slug. Ids are time-sortable. | |
| 6 | CREATE TABLE audit_entries ( | |
| 7 | id TEXT PRIMARY KEY, | |
| 8 | -- RFC 3339 UTC. | |
| 9 | time TEXT NOT NULL, | |
| 10 | -- The workspace's slug: whose log it is in. | |
| 11 | workspace TEXT NOT NULL, | |
| 12 | -- person | agent | workspace | |
| 13 | actor_kind TEXT NOT NULL, | |
| 14 | actor TEXT NOT NULL, | |
| 15 | actor_id TEXT NOT NULL, | |
| 16 | agent TEXT, | |
| 17 | on_behalf_of TEXT, | |
| 18 | run_id TEXT, | |
| 19 | run_kind TEXT, | |
| 20 | credential_id TEXT, | |
| 21 | -- An operation, such as create_issue, or git.push / git.fetch. | |
| 22 | action TEXT NOT NULL, | |
| 23 | -- rest | mcp | git | |
| 24 | surface TEXT NOT NULL, | |
| 25 | -- owner/name | |
| 26 | repo TEXT, | |
| 27 | number INTEGER, | |
| 28 | git_ref TEXT, | |
| 29 | path TEXT, | |
| 30 | -- allowed | denied | |
| 31 | outcome TEXT NOT NULL, | |
| 32 | rule TEXT NOT NULL, | |
| 33 | -- ok, or the failure's code | |
| 34 | result TEXT, | |
| 35 | message TEXT, | |
| 36 | request_id TEXT NOT NULL | |
| 37 | ); | |
| 38 | CREATE INDEX audit_workspace ON audit_entries (workspace, id); | |
| 39 | CREATE INDEX audit_run ON audit_entries (run_id, id) WHERE run_id IS NOT NULL; | |
| 40 | CREATE INDEX audit_target ON audit_entries (repo, number, id) WHERE repo IS NOT NULL; |