Immutable event metadata refs
Technical details
brand_pointerpartner://innovate/brand/lab/v2026-05-01asset_pointerhttps://assets.innovate.test/pci/brand_reasonsnone
Partner brand service
Loading partner-owned brand manifest from /api/session/brand.
- Brand API
/api/session/brand- Boundary
- No browser tenant authority, brand override authority, theme mutation, asset upload, endpoint value, account identifier, physical id, secret, live-data path, or fallback browser storage.
Trusted tenant context
Tenant authority: trusted API session
Tenant: pci_tnt_innovate_lab; partner: innovate; stage: lab; registry version: 3.
No viewer authority inputs were used.
auth.session_refreshed
Module status
- Data Collection enabled / primary Data Collection is enabled by trusted session context.
- Monitoring enabled / integrated Monitoring is enabled by trusted session context.
Audit timeline verified
Audit state remains server-derived and record-only; viewer-supplied tenant, audit stream, event, signing, export, queue, notification, or upload authority is not accepted.
Audit reason codes
reason_code_1none
Audit observability service details
Product hardening audit observability API
Audit observability service
Loading trusted-session audit observability, event-type, authority, downstream, and boundary state from /api/audit/observability-state with a read-only GET.
- Browser authority
- none
- Request policy
- trusted-session-no-query-no-body-no-viewer-authority-no-browser-audit-observability-mutation
- Fallback state
- The audit timeline remains visible if the observability API is unavailable.
| Panel | State | Safe message |
|---|
| Event type | Count |
|---|
| Authority area | State |
|---|
| Seam | State |
|---|
| Boundary | State |
|---|
Audit ledger authority view
Timeline: audit-timeline://cycle_lab_2026_readiness/app-view; API shape: service-ref://api/audit-ledger/timeline/m6.9.
- Authority
- audit-ledger-service
- Display policy
record-only-no-browser-authority- Tenant/stage
pci_tnt_innovate_lab/lab
Ledger verification state
Anchor manifest state
Operator review tasks
Blocked — action neededReview work from ledger events
Use ledger events to jump into assessment, evidence, AOC, and workflow screens. This section creates no audit records and accepts no viewer-provided tenant, event, or object authority.
| Review item | Object/owner | State | Boundary | Open workspace |
|---|---|---|---|---|
Confirm trusted session refreshReview refs
| Operator session context Pci Operator | AcceptedAccepted | Session authority is service-derived; browser-supplied tenant or account inputs remain ignored. | Open workflow task board |
Review saved assessment responseReview refs
| Payment-flow control answer Security Reviewer | Ready for reviewReady For Review | Open the questionnaire row tied to this event; answer content and tenant scope are loaded by the service. | Open assessment workspace |
Check evidence record linkageReview refs
| AOC evidence record Evidence Coordinator | In progressOpen | Evidence files are not rendered here; use the evidence workspace for scan state and response linkage. | Open evidence library |
Resolve sensitive override reviewReview refs
| Monitoring-path override Security Reviewer | Blocked — action neededBlocked | Override work remains blocked until a trusted service re-auth flow authorizes the mutation. | Open assessment workspace |
Prepare AOC package reviewReview refs
| AOC review package Executive Reviewer | Ready for reviewReady For Review | Review package status, signer readiness, and export state without rendering document bodies or signatures. | Open AOC review |
Hash-chain and anchor summary
Anchor, terminal hash, and reason metadata render as service-owned records; no event body or signing control is mounted.
- Sequence range
40-43- Anchor state
- AcceptedAnchored
- Verification
- AcceptedVerified
Hash-chain reason codes
reason_code_1none
Hash-chain refs
stream_idtenant:pci_tnt_innovate_lab:cycle_lab_2026_readinessterminal_event_hashsha256:9090909090909090909090909090909090909090909090909090909090909090anchor_manifest_refaudit-anchor://cycle_lab_2026_readiness/range-40-43/metadata
Audit timeline
Events render as immutable audit ledger records. Payloads, source object contents, and mutation controls are not rendered.
| Seq | Event summary | Occurred | Producer/type | Immutable state | Hash details |
|---|---|---|---|---|---|
40 | Trusted session context was refreshed; viewer-supplied authority inputs remain ignored.Event refs
| Lab sample timestamp: 2026-05-06T13:00Z | pci-platform-apiauth.session_refreshed | AcceptedAppend Only Verified AcceptedVerified | Event hashes
|
41 | Assessment response metadata was written through the service seam and locked append-only.Event refs
| Lab sample timestamp: 2026-05-06T13:05Z | pci-platform-compliance-serviceassessment.response_saved | AcceptedWrite Once Locked AcceptedVerified | Event hashes
|
42 | Evidence metadata ref was accepted; no underlying object or document content is rendered.Event refs
| Lab sample timestamp: 2026-05-06T13:10Z | pci-platform-evidence-serviceevidence.metadata_accepted | AcceptedAppend Only Verified AcceptedVerified | Event hashes
|
43 | Sensitive assessment override requires fresh authentication before any mutation can be attempted.Event refs
| Lab sample timestamp: 2026-05-06T13:12Z | pci-platform-apiassessment.override_reauth_required | AcceptedWrite Once Locked AcceptedVerified | Event hashes
|
Immutable event details
Canonicalization, hashes, actor refs, and object refs are shown as record-only details; browser state does not become audit authority.
| Detail ref | Actor ref | Object ref | Payload hash | Previous hash | Event hash | Canonicalization | Render policy |
|---|---|---|---|---|---|---|---|
audit-detail://cycle_lab_2026_readiness/session-refresh-040 | principalActor ref
| sessionObject ref
| sha256:2020202020202020202020202020202020202020202020202020202020202020 | sha256:1010101010101010101010101010101010101010101010101010101010101010 | sha256:3030303030303030303030303030303030303030303030303030303030303030 | audit-json-c14n-2026-05-01 | AcceptedVerifiedhash-and-record-only |
audit-detail://cycle_lab_2026_readiness/response-save-041 | principalActor ref
| assessment_responseObject ref
| sha256:4040404040404040404040404040404040404040404040404040404040404040 | sha256:3030303030303030303030303030303030303030303030303030303030303030 | sha256:5050505050505050505050505050505050505050505050505050505050505050 | audit-json-c14n-2026-05-01 | AcceptedVerifiedhash-and-record-only |
audit-detail://cycle_lab_2026_readiness/evidence-metadata-042 | serviceActor ref
| evidence_metadataObject ref
| sha256:6060606060606060606060606060606060606060606060606060606060606060 | sha256:5050505050505050505050505050505050505050505050505050505050505050 | sha256:7070707070707070707070707070707070707070707070707070707070707070 | audit-json-c14n-2026-05-01 | AcceptedVerifiedhash-and-record-only |
audit-detail://cycle_lab_2026_readiness/reauth-required-043 | principalActor ref
| sensitive_mutationObject ref
| sha256:8080808080808080808080808080808080808080808080808080808080808080 | sha256:7070707070707070707070707070707070707070707070707070707070707070 | sha256:9090909090909090909090909090909090909090909090909090909090909090 | audit-json-c14n-2026-05-01 | AcceptedVerifiedhash-and-record-only |
Audit conflict state
No audit conflicts are present.
Sensitive mutation re-auth prompts
Prompts are display-only service prompts. No form action, live request, local storage, queue, or mutation control is mounted by this app shell.
| Mutation ref | Surface | Prompt state | Required factor | Audit event | Expires | Policy |
|---|---|---|---|---|---|---|
sensitive-mutation://assessment/override/monitoring-path | Assessment Override | Ready for reviewReauth Required | Fresh Session Or Step Up | aud_evt_reauth_required_043 | Lab sample prompt expiry: 2026-05-06T14:12Z | Prompt policy
|