Audit ​
| Workflow | Type | Description |
|---|---|---|
| audit.audit-run.archive | Atomic | Archive an audit scan run using the soft-delete lifecycle. |
| audit.audit-run.delete | Atomic | Soft-delete an audit scan run. |
| audit.audit-run.get | Atomic | Get one audit scan run for an organization. |
| audit.audit-run.list | Atomic | List audit scan runs for an organization. |
| audit.evidence.record | Atomic | Atomic adapter for audit.evidence.record; required by parent workflow specs: identity.access.review-and-revoke, identity.org.invite-and-provision-role, identity.user.offboard-and-transfer-ownership, policy.service-account.create-least-privilege. |
| audit.export-evidence-pack | Dag | Collect workflow run history, resource evidence, and policy decisions into a downloadable audit evidence package. |
| audit.finding.archive | Atomic | Archive an audit finding using the soft-delete lifecycle. |
| audit.finding.delete | Atomic | Soft-delete an audit finding. |
| audit.finding.get | Atomic | Get one audit finding for an organization. |
| audit.finding.list | Atomic | List audit findings for an organization. |
| audit.software-delivery-slo.scan | Atomic | Evaluate active software deliveries and reconcile deduplicated, auto-clearing findings without accepting caller-forged scan evidence. |
| audit.software-delivery-slo.scan-and-sync | Dag | Run the software-delivery SLO scan, list findings for the audit run, and fan out ticket.sync.software-delivery-slo-finding for each row. |
| audit.workflow-health.scan | Atomic | Audit an organization's workflow-execution health (failed / stuck / deprecated-type runs) and emit trackable findings. |
| audit.workflow-run.aggregate | Atomic | Aggregate workflow-run counts per workflow_type for an organization, optionally scoped to a domain prefix group and a time window. |
| audit.workflow-run.get-history | Atomic | Full transition log for one workflow run, after verifying it belongs to the caller's organization. |
| audit.workflow-run.query | Atomic | List workflow runs for an organization, filterable by workflow-type prefixes, state, terminal status, actor, and time range. |
