Skip to main content

Audit Export Readiness

Audit Export Readiness

Audit export is a preview feature. These notes document the current shape and readiness boundary before self-serve cloud setup is offered.

The export design target is a clear who-did-what trail: actor, action, target, time, outcome, source, reason, and display-safe context.

Last verified: 2026-06-30

Intended Export Shape

  • Compressed newline-delimited JSON audit rows.
  • A sibling manifest with schema version, row count, checksum, object names, range, plugin version, and destination identifier.
  • Masked or hashed references for targets and correlations.
  • Sanitized context only. Secrets, recovery codes, authenticator material, OAuth tokens, and provider credentials must not be exported.

Current Readiness

Amazon S3-compatible export has a local SeaweedFS smoke path for development. Google Drive upload internals exist, including resumable upload for packages larger than 5 MB, but client-facing Google Drive setup is disabled until the HaakCo-managed OAuth broker and Hub account claim flow pass a real staging smoke.

Awthy Hub is a focused account utility for connected-install inventory, claim and reconnect workflows, managed reporting summaries, and account-scoped reporting automation. WordPress remains the owner of local security settings, detailed evidence, and managed-service connection and recovery actions. The expected setup path is: sign in with an email magic link, choose the license/site, copy a short claim code into WordPress, and let the plugin use signed Hub requests for managed Google Drive and Custd setup.

Hub connection setup

The Hub connection panel in WordPress is infrastructure, so it can appear even when a paid audit-export destination is locked. Use it to attach the site to the correct Awthy account before starting managed Google Drive or Custd setup:

  1. Open the Hub account utility and request a magic link for the site owner or license manager.
  2. Choose the expected account, license, and site.
  3. Copy the short claim code from Hub.
  4. Paste the claim code into Awthy Security → Settings → Hub connection in WordPress.
  5. Confirm WordPress shows the connected account/site state without exposing claim codes, install secrets, provider tokens, or raw Hub payloads.

If WordPress reports a reclaim conflict, do not paste claim codes into support channels. Follow the ownership guidance in support-desk recovery.

Free and paid boundaries

Awthy keeps local audit logging and basic security notices separate from paid export destinations:

  • Free installs may see audit-log or audit-export upgrade states before rows, destination credentials, or export jobs are exposed.
  • The Hub connection surface can still be visible so the site owner can connect or repair account ownership.
  • Amazon S3-compatible export, Google Drive export, and managed reporting are paid or preview capabilities and should stay locked until the relevant entitlement is active.
  • A locked destination must explain the boundary without rendering provider setup fields, credentials, or export-job controls.

Reporting and evidence guides

  • Audit Log covers filters, retention, redaction, reference reveal, and safe export expectations.
  • Audit Insights covers severity, outcome, event-type summaries, and time windows.
  • Support Evidence covers display-safe packets, commerce evidence, and support references.
  • WordPress Mutations covers content, configuration, plugin, and redacted diff evidence.
  • File Integrity covers scan roots, snapshots, encrypted redacted diffs, and CLI use.
  • Server Timing covers local server-side timing, route families, percentiles, and claim boundaries.
  • Analytics Reporting covers analytics readiness and the WooCommerce funnel panel.
  • Hub Connection covers claim, reclaim, reconnect, and managed export ownership.

Destinations