Appearance
system-audit
SOM 1.0.0 11 fieldsThe governance audit trail: clearances and suppressions. A suppression targets the held asset. (SOM 1.0 schema)
| Message types | system.audit |
| Typically published by | Compliance and standards desk tools. (SOM Managed Bus) |
| Schema | https://storyobjectmodel.com/schema/1.0/system-audit.schema.json (source at 7297fef) |
| Defined by SOM | 3 of 11 fields |
Governance audit trail (clearances/suppressions). Distinct from som.skills.runs. A suppression targets the held ASSET (the non-airing branch never gets a link). (SOM 1.0 schema)
Required: audit_id, action, target, actor, recorded_at
Unknown fields: refused. The payload lists every field it accepts.
Fields
| Field | Type | Defined by SOM | |
|---|---|---|---|
message_type | optional | string | yes |
audit_id | required | string (uuid) | not yet |
action | required | string | not yet |
target | required | object | yes |
target.kind | required | string | not yet |
target.id | required | string | not yet |
actor | required | object | yes |
actor.actor_id | required | string | not yet |
actor.actor_type | required | string | not yet |
reason | optional | string | not yet |
recorded_at | required | string (date-time) | not yet |
message_type
OptionalType string · Fixed value system.audit
- Repeats the envelope's
message_type, which is what selects this schema. The two must agree: the bus refuses a payload that says something else (payload.message_type_mismatch). (SOM Managed Bus)
Checked by the bus system-audit.type · system-audit.const
audit_id
RequiredType string (uuid)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type · system-audit.format.uuid
action
RequiredType string · Allowed values CLEARED · SUPPRESSED · WITHHELD · OVERRIDDEN
Example SUPPRESSED (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type · system-audit.enum
target
RequiredType object · Unknown fields refused
- A suppression targets the held asset: the branch that never airs never gets a link. (SOM 1.0 schema)
Checked by the bus system-audit.required · system-audit.type · system-audit.additionalProperties
target.kind
RequiredType string · Allowed values LINK · ASSET · TELLING
Example ASSET (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type · system-audit.enum
target.id
RequiredType string
Example pkg-acquit (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type
actor
RequiredType object · Unknown fields refused
- The SOM glossary, Actor (OPEN): An entity (human or system) that performs actions in SOM. Needs one agreed Actor type.
Checked by the bus system-audit.required · system-audit.type · system-audit.additionalProperties
actor.actor_id
RequiredType string
Example automation-01 (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type
actor.actor_type
RequiredType string
Example system (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type
reason
OptionalType string
Example Acquit package suppressed; never linked to air (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.type
recorded_at
RequiredType string (date-time)
Example 2026-06-23T14:30:02.000000Z (from examples/system-audit/suppressed.json)
Not yet defined by SOM
Neither the 1.0 schema nor the SOM glossary says what this field means. Its facts above are exact; its meaning is an open question for the SOM working group.
Checked by the bus system-audit.required · system-audit.type · system-audit.format.date-time
Must be refused
SOM publishes messages that every conformant system must reject. These are the ones that concern this schema, with the rule this bus reports for each, checked by the same validator the gateway runs.
| Case | Why it must fail | Field | Bus rule |
|---|---|---|---|
| audit-flat-actor.json | audit carries actor{} and recorded_at, not flat actor_id | actor | system-audit.required, system-audit.additionalProperties |
Generated from the SOM 1.0 schemas at upstream commit 7297fef, the pack this bus validates against. Quoted SOM text is © the SOM authors, CC BY 4.0, with two changes: working-group decision numbers are shown without their #, and attributions to named working-group members are left out. How to read this reference: SOM 1.0 schema.