A release decision leaves metadata, not a copy of the user.
Each covered record preserves a source reference, normalized instruction class, allowlisted tool family, action, exact version, declared owner, distinct checker, categorical confidence and bounded result. It never stores the prompt or output.
The schema has no field for a raw prompt, prompt hash, output text, tool input or output, source excerpt, member identifier, personal data, arbitrary JSON, free-text reason, private URL or credential.
Seven verified releases have the same minimum audit record.
Confidence is an internal category based on release evidence. It is not a probability, accuracy score or recommendation.
Unknown fields, identities or versions never become approved history.
The public endpoint is read-only. New records can be written only by the bounded internal release recorder.
- Append onlyUpdate and delete attempts are rejected by database triggers.
- Closed taxonomyInstruction, tool, action, confidence and result accept only approved classes.
- Exact source and WorkerSource reference, event digest and Worker drift fail closed.
- No user linkageThe schema cannot accept member identity, email, IP, cookie or personal content.
- No invented tool traceThe tool family is recorded; per-invocation tool calls remain explicitly unverified.
- Independent checkerThe declared owner and checker must be known, active and different AI units.
A release ledger is not a live whole-product operation log.
These gaps block any claim that every AI action, model call or member workflow is recorded.
- Gate 1Instrument new material operations at execution time without storing prompts, private outputs or user identifiers.
- Gate 2Bind each future operation to its actual runtime AI unit and model only when separately proven.
- Gate 3Record per-invocation tool use through a bounded allowlisted taxonomy without retaining raw tool input or output.
- Gate 4Extend coverage to Academy, billing, campaigns, plugins and authenticated member workflows after dedicated privacy review.
- Gate 5Define retention, access review and deletion rules for non-public operational records before creating them.
- Gate 6Measure repeated audit use and detected defects before claiming whole-product operational value.
This audit batch belongs to one exact Worker.
A source, taxonomy, owner, checker, result or Worker change requires a new independent review and a new immutable batch.
- Evidence identifier
qeravio-qtop197-public-ai-operation-decision-log-release-20260820T185710Z- Identity evidence
qeravio-qtop196-public-ai-identity-release-20260820T185710Z- Tested Worker
56bbaf52-e861-4c6d-870e-87c2369a2b78- Completed
- Aug 20, 2026, 6:57 PM
- Immutable decisions
- 7
- Stored user prompts
- 0
- Runtime creators verified
- 0