Another Check-In · A09

Audit and evidence

30 minutes. · 10 slides

Lesson video coming soon. The player below contains a sample video, not this lesson. You can use the written lesson and slide guide now.

Open video on YouTube ↗

Download slide guide (PDF)10 pages · 4.7 MB

Work through the lesson

Use these explanations alongside the slide guide. Expand any section to read its full explanation.

Before the demonstration

  • Your assigned responsibility
  • The correct training record
  • Evidence of the result

Today’s outcome
Custodian preserves original evidence and distinguishes integrity checks from operational truth.

Read the full explanation

Before we begin, check these prerequisites: C01; audit.view for logs; sanitized signed session CSV and trusted public key for verifier. The intended outcome is: Custodian preserves original evidence and distinguishes integrity checks from operational truth. Keep a note of the training identity and date so that you can recognize the result. We will pause before any action that your role or the exercise does not authorize.

A known audit event

  • Open Admin > Audit and narrow to a known training actor/action/time

In this step
Use a known actor, action and time to narrow the audit trail. An auditor may land directly in Audit because Dashboard is outside the default role. That landing behavior does not mean the account failed to sign in.

Read the full explanation

Open Admin > Audit and narrow to a known training actor/action/time. Use a known actor, action and time to narrow the audit trail. An auditor may land directly in Audit because Dashboard is outside the default role. That landing behavior does not mean the account failed to sign in. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Event details

  • Locate a prepared decision or access event and inspect associated details/errors

In this step
Read the associated details and errors to understand the recorded action. An audit event supports accountability but still needs interpretation in its workflow context. Preserve the identifiers needed for a later investigation.

Read the full explanation

Locate a prepared decision or access event and inspect associated details/errors. Read the associated details and errors to understand the recorded action. An audit event supports accountability but still needs interpretation in its workflow context. Preserve the identifiers needed for a later investigation. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Audit-chain evidence

  • Explain hash-chain evidence and use only exposed status/approved operational verification, not an invented Verify Chain button

In this step
Explain the chain using the status or approved operational verification that actually exists. Do not promise a button the interface does not provide. Chain integrity and the truth of the original human claim are separate questions.

Read the full explanation

Explain hash-chain evidence and use only exposed status/approved operational verification, not an invented Verify Chain button. Explain the chain using the status or approved operational verification that actually exists. Do not promise a button the interface does not provide. Chain integrity and the truth of the original human claim are separate questions. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Signed attendance input

  • For the optional verifier extension open /verify with a trusted public key and a proven compatible signed fixture

In this step
Use a trusted public key and a proven compatible signed fixture. Reporting CSV is the wrong input. The dedicated export has a documented round-trip limitation, so a failed verification alone cannot establish that someone altered the evidence.

Read the full explanation

For the optional verifier extension open /verify with a trusted public key and a proven compatible signed fixture. Use known-good v1/v2/v3 fixtures. The dedicated export still has a canonicalization defect documented in file 08; do not promise its successful verification. Use a trusted public key and a proven compatible signed fixture. Reporting CSV is the wrong input. The dedicated export has a documented round-trip limitation, so a failed verification alone cannot establish that someone altered the evidence. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Original and altered copy

  • For a proven compatible fixture only, compare the valid original with a labelled altered COPY

In this step
Keep the original untouched. A labelled altered copy can illustrate verification only after the original succeeds with the chosen fixture. If that prerequisite fails, document the limitation and escalate rather than editing the original to force a pass.

Read the full explanation

For a proven compatible fixture only, compare the valid original with a labelled altered COPY. If no compatible fixture is available, show current-format failure as a limitation and escalate without editing the original. Keep the original untouched. A labelled altered copy can illustrate verification only after the original succeeds with the chosen fixture. If that prerequisite fails, document the limitation and escalate rather than editing the original to force a pass. I will pause here so you can identify the control or result that tells us where we are in the workflow.

Common problems

  • Feeding /exports/checkins.csv into signed verifier
  • disclosing private key
  • treating a signature as proof the original location claim was truthful

A useful support report
The task and record
The expected result
The actual message
The authorized next step

Read the full explanation

Let us consider the mistakes that can disrupt this workflow. Feeding /exports/checkins.csv into signed verifier; disclosing private key; treating a signature as proof the original location claim was truthful. Describe what you expected and what the application actually showed before choosing a remedy. Preserve the relevant record and error. The role responsible for a review or configuration change should make that decision. Do not borrow broader access simply to finish the exercise.

Guided practice

  • Find the logged training action
  • Explain valid versus altered-copy results only with a proven compatible signed fixture; otherwise identify the signed-export round-trip limitation and escalate with the untouched original

Evidence to show
The correct training case
The result or permitted decision
Your explanation of the next step

Read the full explanation

Now it is your turn. Find the logged training action. Explain valid versus altered-copy results only with a proven compatible signed fixture; otherwise identify the signed-export round-trip limitation and escalate with the untouched original. Work within the assigned training role. When you finish, show the result and explain which identity and date it belongs to. If the exercise includes a restricted action, explain the decision and its authorized owner rather than carrying it out without approval.

Practice debrief

  • Correct context and permitted action
  • A result you can trace
  • A clear next step if blocked

Expected result
Custodian preserves original evidence and distinguishes integrity checks from operational truth.

Read the full explanation

The expected outcome is: Custodian preserves original evidence and distinguishes integrity checks from operational truth. Walk me through the record you used and the result you found. Explain these workflow checkpoints in order: Open Admin > Audit and narrow to a known training actor/action/time. Locate a prepared decision or access event and inspect associated details/errors. Explain hash-chain evidence and use only exposed status/approved operational verification, not an invented Verify Chain button. For the optional verifier extension open /verify with a trusted public key and a proven compatible signed fixture. Use known-good v1/v2/v3 fixtures. The dedicated export still has a canonicalization defect documented in file 08; do not promise its successful verification. For a proven compatible fixture only, compare the valid original with a labelled altered COPY. If no compatible fixture is available, show current-format failure as a limitation and escalate without editing the original. For an exception, name the evidence you would preserve and the person with authority to take the next action.