Access administration
People & grants
—
| User | Type | Subdomains | Persistence | Status |
|---|
Audit log
Every action, by every user, including super-admins.
Append-only. UPDATE, DELETE and TRUNCATE are revoked from every API
role — including service_role — at the Postgres privilege layer, which is
checked before RLS. There is no control here, or anywhere in the app, that can alter or
remove an entry. Corrections are appended via a Derrick-only break-glass path that logs
itself.
| When | Actor | Event | Subdomain | Detail |
|---|