Problem
Sensitive transfer investigations are unreliable if audit records can be changed silently or cannot be correlated to a request.
Objective
Deliver a production-quality improvement to transfer and administrative audit storage that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
- Add append-only or hash-chained integrity metadata; include actor, scope, target, correlation ID, outcome, and redacted changes; restrict queries.
Acceptance criteria
- Tampering is detectable; every privileged mutation has one outcome event; authorized operators can filter without exposing secrets.
Required validation
- Integrity-chain, redaction, duplicate-event, query authorization, and correlation tests.
- Existing tests and CI remain passing.
- Add regression coverage for the original failure mode.
- Do not weaken, delete, or skip unrelated tests to obtain a green build.
PR quality bar
- Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
- Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.
Out of scope
- Broad rewrites not required by the acceptance criteria.
- Changes to unrelated services, contracts, or user flows.
Problem
Sensitive transfer investigations are unreliable if audit records can be changed silently or cannot be correlated to a request.
Objective
Deliver a production-quality improvement to transfer and administrative audit storage that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
Acceptance criteria
Required validation
PR quality bar
Out of scope