Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Audit events

id: 01JABC0000000000000000000C
type: policy.evaluated
time: "2026-10-05T13:42:30Z"
executionId: awp-exec-01JABC7Q4M2W9X0Y1Z2A3B4C5D
stepId: investigate
actor:
type: runtime
id: example-runtime
data:
action: github.search_code
decision: allow

Event families: workflow.*, agent.*, tool.*, policy.*, approval.*, artifact.*.

AWP defines the semantics of audit events; implementations may provide tamper-evident storage. The audit.integrity.mode values none, hash-chain and signed describe what a runtime offers.

Normative text: Event envelope, Event types, Tamper evidence.