feat(p9): iios_audit_link table + audit binding at decision points

Task O.3: IiosAuditLink (traceId/correlationId/scopeId/actorRefId/action/
resourceType/resourceId) + recordAudit() helper (reads the current trace from ALS,
best-effort). Written at the decision/mutation points — route approve/deny, AI
accept/reject, meeting summarize, outbound send — so the trace appears in DB and a
decision can be replayed / traced across services (mandated iios_audit_link).
Migration audit-link; resetDb truncates it. 2 tests bind approve/accept to a trace.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-03 01:08:55 +05:30
parent 1d3e18f417
commit 6548b40f17
9 changed files with 161 additions and 1 deletions
@@ -1158,3 +1158,23 @@ model IiosCalendarSyncCursor {
@@unique([providerAccountId])
}
// ─── Observability (P9) ───────────────────────────────────────────
/// Binds an IIOS action to its trace / actor / resource for cross-service causality
/// and "replay a decision" (mandated iios_audit_link). Written at decision points.
model IiosAuditLink {
id String @id @default(cuid())
traceId String?
correlationId String?
scopeId String?
actorRefId String?
action String
resourceType String
resourceId String
createdAt DateTime @default(now())
@@index([traceId])
@@index([resourceType, resourceId])
@@index([scopeId])
}