Security, privacy and audit requirements · C0907
Can an outside auditor read the audit trail, and is their own access logged?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. In the pilot: Append-only by convention (no UPDATE/DELETE routes); no WORM; no scoped auditor role. For reference, REQ-4507 (a high-priority requirement, all three tiers) says auditors must have read-only access by scoped, time-boxed role and their queries must be audited. Check: auditor query appears in audit.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-4507
- Specification priority
- P1 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How long would audit records be kept? Designed
- Would the system detect snooping and unusual access patterns? Designed
See it in context: Audit · Search the help center · Ask a question