# Audit Trail Guide

*Compliance-grade version history for every document Goldie drafts. v1 — 2026-10-01.*

## What it is

An append-only event log (`localStorage` key `silobbyist_audit_v1`) recording every
version of every document produced on SILobbyist — Drafting Studio drafts, Goldie-drafted
documents pasted in from chat, or manually logged text. For each version it stores:

- document name, type, client, matter
- version number (per document, auto-incremented)
- timestamp and author ("Goldie" or "You")
- the full text of that version
- a diff summary vs the prior version (simple line/word diff — words added, words
  removed, changed lines; not a certified redline)
- a SHA-256 hash chained to the previous entry's hash (tamper-evident chain)

## The approval workflow

Draft → review → approved, recorded as **events**, never as editable fields:

1. **Log a version** — from the Audit Trail page form, or the 📥 "Log to audit trail"
   button in the Drafting Studio toolbar (reads the live draft text).
2. **Send for review** — records who asked and when.
3. **Approve** — records the approver's name and timestamp. This is your sign-off;
   an approval event can't be backdated without breaking the chain.

## What the trail proves

- **That a document existed in a specific form at a specific time** — each version
  entry stores the full text plus a hash.
- **Who authored each version** — "Goldie" (AI-drafted) vs "You" (manually written
  or pasted).
- **What changed between versions** — the diff summary shows the shape of each
  revision (use the "View text" toggle to compare full texts side by side).
- **That you approved it before it went out** — approval events with name + timestamp.
- **That nothing was altered after logging** — "Verify chain" recomputes every hash;
  any edit, reorder, or deletion made after the fact shows up as a broken link.

## Retention guidance

- California filers must retain supporting records for **five years**
  (Gov. Code §81004). The audit trail is a *working* record — export the
  **.docx audit report** and file it with your compliance records; the
  browser-local store is not your archive.
- Export habit: after any approval that goes to a client, legislator, or committee,
  export that document's report (.docx) and save it where your other filing records
  live. Monthly full-trail exports are cheap insurance.
- "Delete entire trail" is permanent and breaks the chain for any copies you didn't
  export. Export first, always.

## Limits (v1 — browser-local)

- **Single browser.** The trail lives in this browser's localStorage. Another device
  or browser sees nothing; clearing site data erases it.
- **No access control.** Anyone with access to this browser profile can read, log,
  or delete the trail. It proves what happened *given the log is intact* — it does
  not prove who sat at the keyboard.
- **Tamper-evident, not tamper-proof.** The hash chain *detects* edits/deletions
  made after logging; it cannot *prevent* them. If "Verify chain" reports OK, the
  trail is internally consistent — not independently witnessed.
- **Hashing caveat.** SHA-256 via SubtleCrypto needs a secure context (https). On
  non-secure contexts the trail falls back to a non-cryptographic hash, and the
  affected entries are flagged in the UI and the export.
- **Not the official record.** The trail does not prove a filing was made with the
  Secretary of State or FPPC, and it is not a substitute for those filings. It
  records your drafting and approval work — "it drafts, you file" applies to
  records too.

## For Goldie (KB:MERGE)

Goldie should know the trail exists and route users to it: when the user asks to log
a draft, record it as a version and explain the approval flow (draft → review →
approved) and the .docx audit-report export. Never claim the trail is a certified
legal record or a substitute for FPPC/SOS filing records. The exact prompt section
text lives in the DEPLOY.md entry for this feature.
