Audit Log¶
What To Treat As Auditable¶
- control actions
- protected runtime-cloud actions
- operator write actions that matter to plant history
- deployment and restart actions
Important Boundary¶
truST can provide runtime-side evidence, but plant-grade compliance usually also needs:
- site policy
- operator identity model
- external retention policy
- local runbook and escalation rules