The Audit Service is the append-only audit trail for PHI access, consent changes, research queries and merge operations.
WORM semantics
Audit records are never updated or deleted — only appended and queried.
Could not build diagram for model "example-healthcare".
Receives audit events from all services.
WORM-style storage for audit trail.
API for compliance officers to query audit.
The Audit Event Collector accepts events from all services.
Audit Storage writes immutable, encrypted partitions.
The Query API serves compliance officers.
Search and export endpoints for audit investigation are on the Overview tab.
Contract
Querying audit logs is itself audited — officers cannot browse without a trail.