Read the audit trail
Optional: hand this page to your coding agentThe steps work by hand too.Show the whole prompt
Read https://intentius.io/terragucci/guides/read-the-audit-trail/.
Download audit.jsonl from the top of my reports prefix with a read-only identity and tell me, for the project and wave I name,
who approved it, which digest, when it applied, and any override or refusal, each with its evidence link.
Read only: do not run `terragucci audit` without `--check`, and write nothing to the bucket.
Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.Result
Section titled “Result”Each approval, apply and override in your projects, traced to the person behind it and linked to its evidence.
Prerequisites
Section titled “Prerequisites”| You need | Why |
|---|---|
| Reports in a bucket | the record and the wave reports it reads live there |
A terragucci audit step in the estate job, before terragucci estate |
the step writes the record (Write it) |
A read-only identity on the bucket, and jq |
to fetch and query the record |
Storage
Section titled “Storage”The record is three objects at the top of your reports prefix, beside estate.html:
| Object | Holds |
|---|---|
audit.jsonl |
one entry per line: every approval, apply, override, refusal, lock release, state export and migration |
audit.html |
counts by kind, each project’s ledger state, and the newest 1000 entries with their evidence links |
audit.json |
the summary the estate page reads to link audit.html |
terragucci builds it from two sources it does not hold itself: the approval ledger on each repo’s chant/lifecycle branch, and the tf-apply wave reports in the bucket.
-
Open the page, or fetch the record. The
terragucci auditstep’s log ends with a signed link toaudit.html; for the lines, use the store’s own CLI:Terminal window aws s3 cp s3://acme-terragucci/reports/audit.jsonl . -
Find the approvals of a wave. On an
approvalentry,whonames the approver anddigestthe plan digest it binds;resultsays how it was signed:Terminal window jq -c 'select(.project == "github.com/acme/network" and .what == "wave-2") | {at, kind, who, digest, result}' audit.jsonl{"at":"2026-10-08T09:12:44.000Z","kind":"approval","who":"dana","digest":"sha256:4be1...","result":"unsigned"}{"at":"2026-10-08T09:20:03.000Z","kind":"apply","who":"dana","digest":"sha256:4be1...","result":"applied"}Under
approval: ledger,whois the name the approver gave anddetail.committed_byis who pushed the line. Undersealed,detail.signeris the key’s owner, checked against the signers file at base (what each mode proves). -
Match the apply to its approval. On the
applyentry,detail.approvalholds theidof the approval it applied under:Terminal window jq -c 'select(.kind == "apply") | {at, project, what, who, digest, approval: .detail.approval, commit: .detail.commit}' audit.jsonlevidence.urlon each entry opens the commit onchant/lifecyclethat added the approval, or the wave’sreport.html. -
List the overrides.
whois the person who let the plan through, anddetail.reasonwhy:Terminal window jq -r 'select(.kind == "override") | [.at, .project, .what, .who, (.detail.rules | join(",")), .detail.reason] | @tsv' audit.jsonlThe wave that applied under it lists the root in
detail.overrideson itsapplyentry. -
List what did not go out:
Terminal window jq -r 'select(.kind == "refused" or .result == "failed") | [.at, .project, .what, .result, .evidence.url // .evidence.key] | @tsv' audit.jsonlOn a
refusedentry,resultgives the reason, such aschanged-after-approval;detailnames the roots that moved or the rules that denied.
Check the record
Section titled “Check the record”--check rebuilds the entries from the ledgers and reports and writes nothing. It exits 1 naming each entry the record lacks:
npx --yes @intentius/terragucci audit --checkA removed ledger line shows as approval-revoked or override-revoked, with the commit that removed it; the record keeps the line it revoked.
- The audit trail lists every kind, field and retention rule.
- Query the estate with SQL answers questions over the reports and the audit trail in SQL.
These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.