# AL097 AI agent audit trail schema worksheet

Define material event boundaries, stable identities, versions, protected references, authorization, action, state, correction and lifecycle before accepting an event producer.

## Fifteen field groups

1. Event ID, envelope schema and typed payload version
2. Occurrence, observation, ingestion time and clock evidence
3. Tenant, workflow, run and parent/delegated run
4. Parent event, cause, operation, attempt, trace and span
5. Agent, model, configuration, instruction, policy and tool versions
6. Requester, effective identity, role and delegation chain
7. Input provenance, evidence segment and transformation lineage
8. Policy decision, human decision, expiry and revocation
9. Requested action, target and logical operation identity
10. Validated parameters, data class, redaction and protected digest
11. Before/after state and authoritative target observation
12. Outcome, error, retry owner and attempt lineage
13. Reviewer, appended correction and derived-view rebuild
14. Audit access, search, export and integrity monitoring
15. Retention class, hold, deletion verification and tombstone

## Release rule

Keep release blocked when material event boundaries are missing, tenant or causal identity is ambiguous, authorization does not bind to the action, authoritative state is unreconciled, prohibited secrets enter general logs, history is overwritten, or retention cannot be verified. AL097 remains `NOT_RELEASED` until corrected cases receive independent review and a full rerun.
