You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(session): persistent audit log of every model change, with tx audit #414
Answer "who changed this, when, and was it an agent?" after the session that made the change has ended. This is needed for trust and governance once agents edit models through tx mcp.
What do we do today?
The change journal records every write with origin.client and origin.kind (ADR 0001 §4 and §7), for every client: shell, tx ui, tx mcp, tx serve.
Both live only in memory. Once the session ends or reloads, the record is gone. One-shot tx commands leave no record.
What would tx do?
Append-only JSON Lines log, one line per committed transaction, with:
time;
client kind and name (mcp:claude-code, ui, shell, cli);
agent or user, and the OS user;
the source (model path or server/database);
each change: object path, LineageTag, property, before and after values (long expressions truncated, with a hash);
the undo, redo or reload kind.
Default location:.tomix/audit.jsonl next to a TMDL source (git-ignorable, or committed by choice), and the per-user state directory for server sources. Configured with tx config set audit.path / audit.enabled.
Part of #408. Size: S–M · Depends on: #379, #391
What are you trying to do?
Answer "who changed this, when, and was it an agent?" after the session that made the change has ended. This is needed for trust and governance once agents edit models through
tx mcp.What do we do today?
origin.clientandorigin.kind(ADR 0001 §4 and §7), for every client: shell,tx ui,tx mcp,tx serve.session.changes(feat(serve): session.changes — net changes since the save point, with authors #391) lists the net changes since the save point.txcommands leave no record.What would tx do?
Append-only JSON Lines log, one line per committed transaction, with:
mcp:claude-code,ui,shell,cli);LineageTag, property, before and after values (long expressions truncated, with a hash);Default location:
.tomix/audit.jsonlnext to a TMDL source (git-ignorable, or committed by choice), and the per-user state directory for server sources. Configured withtx config set audit.path/audit.enabled.Covers every client, not only MCP. One-shot mutating commands write a line too, through the same journal path once refactor(app): run handlers against an open session #345 lands.
tx auditreads it:Never logs secrets: connection strings and credentials are left out of before/after values.
Acceptance criteria
tx mcp, an undo intx ui, and a one-shottx seteach produce one log line with the right client.tx audit --pathfinds an edit made in an earlier session.--output-format jsonis supported, and the schema is locked by a snapshot test.