REQ-NFR-013
Audit log append-only at the DB role level
What
The audit log SHALL be append-only at the DB role level.
Acceptance
Permission test denies UPDATE/DELETE on audit_log.
Category
Security.
established project management guidelines Mapping
DB-role-level append-only enforcement is an integration-layer tamper control.