REQ-NFR-013

Audit log append-only at the DB role level

ID
REQ-NFR-013
Category
Non-Functional Requirements
Status
approved
Priority
P0
Created
2026-05-10T18:01:20.975Z
Approved
2026-05-10T18:03:07.518Z
Updated
2026-05-10T18:03:07.518Z

What

The audit log SHALL be append-only at the DB role level.

Acceptance

Permission test denies UPDATE/DELETE on audit_log.

Category

Security.

established project management guidelines Mapping

Primary Knowledge Area
Integration Management
Secondary KA
Risk Management
Primary Process Group
Monitoring & Controlling
established project management guidelines Deliverable
Audit Log

DB-role-level append-only enforcement is an integration-layer tamper control.