audit.evidence.record
Atomic adapter for audit.evidence.record; required by parent workflow specs: identity.access.review-and-revoke, identity.org.invite-and-provision-role, identity.user.offboard-and-transfer-ownership, policy.service-account.create-least-privilege.
Overview
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-identity |
| Version | 1.0 |
Input Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
workflow_run_id | string | No | — | DAG-stamped parent run id. |
organization_uuid | uuid | Yes | — | Organization UUID for tenant isolation. |
actor | string | No | — | User or service actor initiating the workflow. |
dry_run | boolean | No | — | Validate and plan without mutating external resources. |
review_scope | json | No | — | Access review scope. |
reviewers | list | No | — | Reviewers. |
revoke_policy | json | No | — | Revocation policy. |
notify_channels | list | No | — | Notification channels. |
dependency_context | json | No | — | Prior DAG step output used by this adapter. |
email | string | No | — | Invitee email. |
role | string | No | — | Organization role. |
invitation_message | string | No | — | Invitation message. |
notification_channels | list | No | — | Notification channels. |
user_uuid | uuid | No | — | User UUID to offboard. |
replacement_user_uuid | uuid | No | — | Replacement owner user UUID. |
transfer_policy | json | No | — | Ownership transfer policy. |
revoke_tokens | boolean | No | — | Revoke API tokens. |
service_account_name | string | No | — | Service account name. |
provider_type | string | No | — | Provider key. |
connection_uuid | uuid | No | — | Provider CloudConnection UUID. |
required_actions | list | No | — | Required actions/capabilities. |
credential_policy | json | No | — | Credential issuance policy. |
Output Schema
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
status | string | No | — | Adapter terminal status. |
summary | json | No | — | Adapter output summary. |
resource_refs | json | No | — | Provider/app resource references produced by adapter. |
warnings | list | No | — | Non-fatal adapter warnings. |
failure_reason | string | No | — | Adapter failure reason. |
failed_step | json | No | — | Failed step. |
failed_layer | json | No | — | Failed layer. |
failed_at_state | string | No | — | Failed at state. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
failed_at | string | No | — | Failure timestamp. |
States
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
PENDING | Yes | No | — | execute | — |
COMPLETED | No | Yes | Yes | — | — |
FAILED | No | Yes | No | — | — |
State Diagram
Transitions
| From | Action | To | Description |
|---|---|---|---|
PENDING | execute | COMPLETED | — |
* (any state) | fail | FAILED | — |
API Usage
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "audit.evidence.record",
"initial_data": {
"organization_uuid": "value"
}
}