Evidence

Audit

Review the decision stream for identity, RBAC, tenant, app, recovery, session, and agent operations.
Evidence first Open audit log
1 OS admins System-wide administrators with guarded bootstrap history 2 Pending approvals 1 blocked items need explanation or remediation 4/4 App clients Shared auth, redirects, origins, OpenAPI, MCP, and A2A readiness 17 High-risk permissions Role, identity, recovery, and break-glass actions require gates

Useful Drill-Downs

existing tools