Skip to content

Compliance evidence bundle

@kindgi/specs/compliance-evidence.schema.json, schema version 1.1.0.

One evidence record emitted by the Kindgi runtime for compliance / audit consumption. Derived from provenance DAG + policy decisions + audit log. Consumed by a ComplianceProvider, whose adapters forward evidence to a compliance platform or a SIEM. The optional Ed25519 signature provides tamper detection.

  • id (string, required): Unique evidence record ID.
  • tenantId (string, required)
  • projectId (string): Content-scope anchor: the project the underlying audit event belongs to. Absent for tenant-level events (e.g. authz decisions, tenant-level admin actions).
  • kind (string, required): The compliance-relevant event class. Open set: evidence is a classifier lens over the audit stream, and a deployment can mark any audit-event kind exportable. examples lists the built-in kinds; consumers must tolerate kinds they do not know.
  • timestamp (string (date-time), required)
  • actor (object): Who performed the action.
    • kind ("user" | "agent" | "system" | "admin" | "external")
    • id (string)
    • ipAddress (string)
    • userAgent (string)
  • subject (object): What the action was performed on.
    • kind (string)
    • id (string)
  • outcome ("allowed" | "denied" | "succeeded" | "failed" | "escalated"): Result of the action, for kinds where this is meaningful.
  • payload (map of any, required): Kind-specific evidence detail. For policy-decision: the rule that matched, the request context. For config-change: before/after diff. For secret-rotation: which secret, when. Etc.
  • provenanceRef (object): Optional back-reference to the provenance DAG that produced this evidence.
    • runId (string)
    • nodeId (string)
  • signature (object)
    • algorithm ("ed25519", required)
    • keyId (string, required)
    • value (string, required)
    • signedAt (string (date-time), required)