01 · Recording
One audit contract for the whole system
Every action uses the same typed audit record: a fixed action code, a trusted context (who, through which source, from which IP) and a policy per action that decides whether a reason and the before-and-after state are required.
Sensitive values are redacted before storage, and each event gets a checksum so you can verify afterwards that it has not been altered.

