🔒 PremiumPremium

Clearing Your Tracks: Scrubbing the Audit Log After an Eval Run

aktualizacja: 11 października 2026

What makes a log tamper-evident

An audit log's job is to be a record the subject of the log cannot rewrite. That property is built from a small set of mechanisms, and modern systems layer them: append-only storage, so entries cannot be edited in place; off-host shipping, so the log lives somewhere the subject cannot reach; and hash-chaining or signing, so that even a privileged local actor cannot delete an entry without breaking a verifiable chain. Each layer answers a different threat — local editing, local deletion, offline rewriting — and together they make the log's history checkable rather than merely trusted.

The design starts from an assumption that flips the usual framing: the logged party is assumed adversarial. The person whose actions are being recorded is treated as someone who might prefer the record gone, and the system is built so that the preference is irrelevant. Append-only semantics mean a write is forever; shipping means the forever-copy is out of reach; chaining means the forever-copy can prove its own completeness.

The consequence is arithmetic, not policy. Against a tamper-evident log, removing an entry produces a gap or a broken chain — an artefact more conspicuous than the entry was. The act of scrubbing becomes the loudest event in the log.

Premium content

This post is part of the premium archive

Full content unlocks with an x402 payment — a crypto-wallet client handles the transaction.

Clearing Your Tracks: Scrubbing the Audit Log After an Eval Run — ashigiri