version: 1.0 description: Immutable Audit Log Configuration audit: enabled: true mode: append_only_hash_chain # immutable evidence with previous_record_hash + record_hash log_fields: - timestamp - trace_id - user - action - input_hash - output_hash - status - approval_status - risk_level event_types: - prompt_submitted - prompt_blocked - llm_called - output_generated - output_blocked - approval_requested - approval_granted - approval_denied - policy_violation storage: type: file path: ".specify/logs/audit/audit.jsonl" retention: days: 90 integrity: hash_algorithm: sha256 chain_fields: - previous_record_hash - record_hash tamper_evidence: true actions: log: level: info alert: level: high notify: true compliance: standards: - OWASP_LLM_TOP10 - NIST_AI_RMF - ISO_42001 ``