ONTO-RECONCILE-1 Phase 6 — bounded audit aggregation over a time window.
Two substrate queries (counts grouped by action+actor; recent-actions
LIMIT N). recent_actions rows expose only metadata-shaped fields per
the privacy contract — caller-supplied content (evidence_ref,
before_json, after_json) is excluded.
Authentication: routes inherit ScopePolicy.team_required from
create_router(...)'s default — verified at base_router.py:62.
Audit data is workspace-scoped via FalkorDB graph_name isolation.
Note on group_by: today the substrate always groups by (action, actor)
jointly and folds into by_action and by_actor. The parameter is
accepted (and validated against {"action", "actor"}) for forward
compatibility, but additional grouping is not yet implemented.
Query Parameters
ISO-8601 lower bound (inclusive)
ISO-8601 upper bound (inclusive)
Subset of {'action','actor'}
Cap on recent_actions rows
Response Body
application/json
application/json
curl -X GET "https://example.com/memory/ontology/audit/summary?since=string"null{
"detail": [
{
"loc": [
"string"
],
"msg": "string",
"type": "string",
"input": null,
"ctx": {}
}
]
}Get Async Ingest Status
Poll the status of an async ingest run. ``status`` distinguishes ``abandoned`` (the content was accepted and is not known to have been stored) from ``unknown_run_id`` (no such run). Before the run ledger these were the same reply, so a caller could never learn that content was lost. Goes through the scoped facade, which refuses a run belonging to another workspace. The previous implementation constructed the transport here and read the status hash directly, so any authenticated caller could read any tenant's run.
Get Audit Trail
Get complete audit trail for an item. Returns detailed log of all changes with user, timestamp, and change details. Suitable for compliance reporting (HIPAA, GDPR, SOC2).