Audit trail
Every governed query, with its principal, applied policy, SQL and content hash.
Retrieval is by date range so an auditor can reconstruct who asked what, under which policy, for any period (§4, FR-11).
What this log stores. The query, the asking principal, the applied policy, the SQL, the row count and a content hash of the result set — not the result rows themselves. Where evidence is retained for a saved report or a trace, PII fields are held as tokenised references rather than raw values, so an erasure request is honoured by crypto-shredding the token keys without mutating the append-only chain (FR-11, data-handling).
Principal. The principal shown is a configured demo value in this build, not an authenticated per-user identity. §8 requires SSO/OIDC against BoM AD with the principal derived from the session token, and explicitly rejects a shared static token as production auth. Nothing here should be read as per-user scoping being enforced.
Declines. 0 of 0 entries in view are declines or denials, shaded and labelled with their cause. FR-13 treats honest declination as a logged control, whose rate is measured against the curated question set (§3) rather than being hidden.