Operating standards

Authorized, bounded, reviewable, and evidence-led.

These standards govern how AuditTrace describes, designs, evaluates, and supports preservation and verification work.

Declared scope

Every task begins from a named system, workflow, device, dataset, or event boundary.

Authorization

Work applies only to owned systems or systems and data covered by current, explicit authorization.

No silent expansion

Discovery does not become permission to broaden collection, execution, or review.

Evidence before claims

Conclusions remain tied to preserved artifacts, documented limits, and reproducible checks.

Human final authority

Agents and tools do not self-approve scope, releases, exports, evidence promotion, or consequential actions.

Non-surveillance

AuditTrace does not position continuous person monitoring, behavior scoring, or covert observation as preservation.

Provenance and integrity

Artifacts should retain enough source, timing, handling, and verification context for later review.

Reproducibility

Supported comparisons and verification steps should be documented and repeatable.

Claim discipline

AuditTrace does not claim perfect proof, complete visibility, guaranteed compliance, or automatic legal sufficiency.