Audit events
id: 01JABC0000000000000000000Ctype: policy.evaluatedtime: "2026-10-05T13:42:30Z"executionId: awp-exec-01JABC7Q4M2W9X0Y1Z2A3B4C5DstepId: investigateactor: type: runtime id: example-runtimedata: action: github.search_code decision: allowEvent families: workflow.*, agent.*, tool.*, policy.*, approval.*, artifact.*.
AWP defines the semantics of audit events; implementations may provide tamper-evident storage. The audit.integrity.mode values none, hash-chain and signed describe what a runtime offers.
Normative text: Event envelope, Event types, Tamper evidence.