Actor & context
Who/what acted, organization/workspace, subject/context and session assurance where relevant.
TRUST
Create reviewable evidence for sensitive actions, policy decisions, configuration changes and integration outcomes.
Who/what acted, organization/workspace, subject/context and session assurance where relevant.
Action requested, authorization/policy result and reason category.
Policy/configuration/model/interface version associated with the action where material.
Timestamp, correlation, success/failure and resulting state or approval evidence.
Audit evidence is access-controlled and is not the same as a public evidence register; patient data and secrets are not published.
Evidence requests are handled according to authorization, purpose and retention; the public website is not a direct audit-log export channel.
The evidence model should distinguish authentication, access, business decisions and state changes while sharing correlation identifiers that reconstruct the end-to-end action.
Record the authenticated actor/workload, organization/workspace and session/device context appropriate to the event.
Identify the affected patient/order/document/resource or configuration object and the action/decision performed.
Use reliable timestamps plus request/workflow correlation so distributed events can be assembled without copying sensitive payloads into logs.
Record success/failure and, for approvals/overrides/corrections, the decision reason or reference required by policy.
Audit is useful only if collection, access and retention are controlled.