Skip to content

feat(session): persistent audit log of every model change, with tx audit #414

Description

@bgarcevic

Part of #408. Size: S–M · Depends on: #379, #391

What are you trying to do?

Answer "who changed this, when, and was it an agent?" after the session that made the change has ended. This is needed for trust and governance once agents edit models through tx mcp.

What do we do today?

What would tx do?

  • Append-only JSON Lines log, one line per committed transaction, with:

    • time;
    • client kind and name (mcp:claude-code, ui, shell, cli);
    • agent or user, and the OS user;
    • the source (model path or server/database);
    • each change: object path, LineageTag, property, before and after values (long expressions truncated, with a hash);
    • the undo, redo or reload kind.
  • Default location: .tomix/audit.jsonl next to a TMDL source (git-ignorable, or committed by choice), and the per-user state directory for server sources. Configured with tx config set audit.path / audit.enabled.

  • Covers every client, not only MCP. One-shot mutating commands write a line too, through the same journal path once refactor(app): run handlers against an open session #345 lands.

  • tx audit reads it:

    tx audit                                   # recent entries, newest first
    tx audit --client mcp --since 1d
    tx audit --path "Sales/Total Sales"
  • Never logs secrets: connection strings and credentials are left out of before/after values.

Acceptance criteria

  • An edit through tx mcp, an undo in tx ui, and a one-shot tx set each produce one log line with the right client.
  • The log survives a session restart, and tx audit --path finds an edit made in an earlier session.
  • --output-format json is supported, and the schema is locked by a snapshot test.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:devexbuild, CI, tests, contributor toolingenhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions