Audit and compliance
What the record proves, where the evidence lives, and what it does not prove.
Before you start: nothing installed, and no administrative rights — every page here is a reading task. Concepts is worth ten minutes first if the vocabulary is new.
You are reading this because you have to establish what happened, by whom, and whether the record of it can be relied on — for a surveillance audit, for an internal review, or after an incident.
This section is written for that job. It does not describe features. It describes what is written down, which of the things written down can be checked by someone who does not trust the machine that wrote them, and where that stops.
Start with the boundary, because it decides how you read everything else
A standard certifies your organisation's management system. It does not certify a vendor's product, and no product can make you compliant. Saphan Studio does not come certified and this section makes no conformity claim on your behalf. Conformity is your auditor's verdict.
What the product does is narrower. Work advances only through recorded decisions that carry their evidence, so the artefacts an auditor asks for exist because of how the work happened — not because they were collected around it afterwards. That is the whole claim, and the rest of this section is the detail behind it.
Read it in this order
The order below is the order an audit walk-through takes — properties first, then where the evidence sits, then one change followed backward, then the checks you can run without us.
| Read this | To answer |
|---|---|
| What the record guarantees | Which properties hold by construction rather than by convention, and which kind of record carries which strength. |
| Where the evidence lives | What is written down, which files are only projections of it, and which surface you read each one from. |
| Tracing one change backward | The walk-through itself, from a merged change back to the decision, the review, the order and the cost. |
| Checks you can run yourself | The verifications that do not depend on trusting the control plane that produced the record. |
| The questions a framework makes an auditor ask | Where in this record each of those questions is answered, and where it is not. |
| What this does not prove | The limits, stated as limits. |
If you only read one page
If your job is to find the gap rather than to confirm the story, start at what this does not prove. It is the shortest route to the edge of what this record can support, and it is the page the rest of the section should be judged against.
Two words that are not interchangeable here
Saphan is the company. Saphan Studio is the product. Where this section says the product records something, it means the software you run on your own machines — not a service operated for you.