Skip to content

Add publishing audit and provenance for humans, API clients, and agents #1682

Description

@ascorbic

Goal

Publishing-sensitive actions should leave enough provenance to answer who changed content, what path they used, and when.

Scope

Track provenance for humans in the admin, API clients, and agent/MCP workflows. Include publish, unpublish, schedule, unschedule, discard, restore, trash, and permanent delete.

Acceptance criteria

  • Publishing-sensitive actions record actor identity and access path.
  • Agent/API actions are distinguishable from admin UI actions.
  • The audit data is available to admins or documented for follow-up UI work.
  • The design does not expose secrets or bearer tokens in audit records.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions