Security & privacy · Audit

Audit Logging Compliance Audit

Audit one security, compliance, financial, admin, or data-governance audit-log boundary. Focus on event completeness, integrity, privacy, retention, queryability, and operational usefulness.

Vibe Coding 1.3.0 · vibe-security · English technical instructions

← Back to search

Use this workflow

Use this workflow in Codex or Claude Code with the free Vibe Coding plugin. Choose your assistant and prompt language, then add your task details after the prompt.

Operation

Inspect the named boundary and report supported findings. Do not edit product code. Include concrete evidence, impact, the owning source, one remediation direction and a meaningful validation route. Severity follows actual impact, not a category example.

Goal and scope

Audit one security, compliance, financial, admin, or data-governance audit-log boundary. Focus on event completeness, integrity, privacy, retention, queryability, and operational usefulness.

Domain invariants

  • Material actions produce audit events with actor, subject, action, resource, tenant/scope, timestamp, outcome, reason, correlation/request ID, and safe metadata.
  • Audit events are emitted at the authoritative owner layer and are not skipped by alternate API, worker, webhook, admin, or bulk paths.
  • Logs avoid sensitive payload leakage and support retention/export/deletion requirements defined by the product/repo.
  • Audit records are durable enough for the stated use case and have tests or operational gates.

Audit method

Trace the selected action across API/UI/jobs/webhooks/admin paths, policy decisions, persistence, event emission, log sinks, retention, query surfaces, and tests. Separate application audit logs from generic debug logs.

Workflow ID: audit-logging-compliance-audit · View the versioned source · Shared workflow and authority rules