audit.export-evidence-pack ​
Collect workflow run history, resource evidence, and policy decisions into a downloadable audit evidence package.
Collect workflow run history, resource evidence, and policy decisions into a downloadable audit evidence package.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-audit |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
workflow_run_id | string | No | — | DAG-stamped parent run id. |
organization_uuid | uuid | Yes | — | Organization UUID for tenant isolation. |
actor | string | No | — | User or service actor initiating the workflow. |
idempotency_key | string | No | — | Caller-supplied idempotency key for safe retries. |
dry_run | boolean | No | — | Validate and plan without mutating external resources. |
subject_ref | string | Yes | — | Audited subject reference. |
time_range | json | No | — | Time range filter. |
include_workflow_history | boolean | No | — | Include workflow history. |
include_policy_evidence | boolean | No | — | Include policy evidence. |
destination | json | No | — | Export destination. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | No | — | Organization uuid. |
workflow_run_uuid | uuid | No | — | Workflow run uuid. |
status | string | No | — | Status. |
summary | json | No | — | Summary. |
resource_refs | json | No | — | Resource refs. |
warnings | list | No | — | Warnings. |
completed_at | string | No | — | Completed at. |
compensation_trigger | string | No | — | Compensation trigger. |
compensation_results | json | No | — | Compensation results. |
audit_workflow_run_query | json | No | — | Output state_data from DAG step audit_workflow_run_query. |
audit_workflow_run_get_history | json | No | — | Output state_data from DAG step audit_workflow_run_get_history. |
audit_workflow_run_aggregate | json | No | — | Output state_data from DAG step audit_workflow_run_aggregate. |
audit_workflow_health_scan | json | No | — | Output state_data from DAG step audit_workflow_health_scan. |
storage_bundle_upload | json | No | — | Output state_data from DAG step storage_bundle_upload. |
failure_reason | string | No | — | Failure reason. |
failed_step | json | No | — | Failed step. |
failed_layer | json | No | — | Failed layer. |
failed_at_state | string | No | — | Failed at state. |
error | string | No | — | Error. |
error_type | string | No | — | Error type. |
failed_at | string | No | — | Failed at. |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | 01_audit_workflow_run_query | audit.workflow-run.query | — |
| 2 | 02_audit_workflow_run_get_history | audit.workflow-run.get-history | — |
| 3 | 03_audit_workflow_run_aggregate | audit.workflow-run.aggregate | — |
| 4 | 04_audit_workflow_health_scan | audit.workflow-health.scan | — |
| 5 | 05_storage_bundle_upload | storage.bundle.upload | — |
Execution Flow ​
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
audit.workflow-run.query | audit_workflow_run_query |
audit.workflow-run.get-history | audit_workflow_run_get_history |
audit.workflow-run.aggregate | audit_workflow_run_aggregate |
audit.workflow-health.scan | audit_workflow_health_scan |
storage.bundle.upload | storage_bundle_upload |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "audit.export-evidence-pack",
"initial_data": {
"organization_uuid": "value",
"subject_ref": "value"
}
}