On this page
Audit controls and responsibilities
Find the record controls and access-management guidance needed to preserve useful audit evidence.
Use an ADMIN account to configure auditing. Decide separately whether the
table needs retained history for workflows such as merge undo.
Enable the controls
For a new table, include auditable:true and history:true in its creation
request when both are required. The table must reference a valid dataset. See
Configure tables for the complete creation contract.
For an existing Aurelia table, enable auditing with:
curl --fail-with-body --silent --show-error --request PUT \
--header "Authorization: Bearer ${GOLDEN_TOKEN}" \
"${GOLDEN_URL}/api/tables/audit/sample_customer?enabled=true"
This operation is idempotent. Read its reported outcome rather than assuming that every successful call changed the setting. It does not enable history.
Verify useful evidence
Perform a controlled, reversible change in a disposable entity, with a comment.
The API correction exercise includes a verified
change and restoration. Read the affected record’s /audit endpoint and check
that the expected event and comment appear. Verify that your steward can read
it and your viewer cannot. Both roles still need the appropriate data access.
An empty audit list alone cannot distinguish no changes from a previous gap. Check the table setting and the period you actually need to investigate.
Disable and resume auditing
Use the same endpoint with enabled=false only when the resulting evidence gap
is acceptable. Add a URL-encoded comment query parameter explaining the change.
Disabling retains existing events; later changes during the gap are not
reconstructed when auditing resumes. A failure must be resolved before treating
the setting as changed.
Preserve useful attribution
- Give each human their own Golden user.
- Give each integration its own access token.
- Use meaningful stewardship comments where an operation accepts one.
- Limit role assignments to each identity’s workflow.
- Agree retention and export requirements for audit evidence.
See Audit and history for the distinction between events and retained records, and Inspect changes for investigation and recovery limits.