pub struct AuditEvent {
pub timestamp: DateTime<Utc>,
pub actor: ActorRef,
pub namespace: String,
pub verb: String,
pub decision: AuditDecision,
pub deny_reason: Option<String>,
pub obligations: Vec<Obligation>,
pub gate_impl: String,
pub session_id: Option<String>,
pub op_index: Option<u32>,
pub ref_resolution: Option<RefResolution>,
}Expand description
Structured audit record emitted once per gate consultation.
JSON field names are stable; events reach tracing and the configured event store. See
crates/khive-gate/docs/api/audit-events.md.
Fields§
§timestamp: DateTime<Utc>Wall-clock timestamp of the gate check (UTC, RFC3339 in JSON).
actor: ActorRefCaller identity as given to the gate.
namespace: StringNamespace in which the verb was invoked.
verb: StringVerb being dispatched.
decision: AuditDecisionGate outcome — "allow", "deny", or "gate_unavailable".
deny_reason: Option<String>Deny reason, present only when decision == "deny".
obligations: Vec<Obligation>Obligations on allow; always serialized and empty on deny or outage.
gate_impl: StringName of the gate implementation that produced this decision.
session_id: Option<String>Correlation token — GateContext::session_id when present, else None.
op_index: Option<u32>Original request parser position, not completion order. Unknown outside a composed-request scope and in historical envelopes.
ref_resolution: Option<RefResolution>Reference provenance; absent together with op_index when unknown.
Implementations§
Source§impl AuditEvent
impl AuditEvent
Sourcepub fn with_operation_attribution(
self,
operation: Option<OperationAttribution>,
) -> Self
pub fn with_operation_attribution( self, operation: Option<OperationAttribution>, ) -> Self
Attach provenance established by a request runner. A direct gate consultation without that scope explicitly remains unattributed.
Sourcepub fn from_check(
req: &GateRequest,
decision: &GateDecision,
gate_impl: &str,
) -> Self
pub fn from_check( req: &GateRequest, decision: &GateDecision, gate_impl: &str, ) -> Self
Project one request/decision pair into a timestamped stable audit envelope.
See crates/khive-gate/docs/api/audit-events.md.
Project a gate infrastructure failure into the stable audit envelope.