AUDITOR — production wired (read-only)

Sample rows removed. Evidence projections via CASA_API.auditportal. Cannot mutate source records, permissions, publication, refunds, or audit history.

AUDITOR — evidence / reports / privacy / exports

Evidence is read-only and field-allowlisted. Observations do not mutate source. Exports need purpose, legal basis and dual approval for sensitive sets; CSV is formula-escaped, encrypted with a one-time DEK, and download TTL is not extended on retry. Privacy deletion queues soft-delete for Prompt 24.

Read-only

Auditor workspace has no Add/Edit/Delete/Approve/Refund/Publish controls. Optional audit observations only.

Campaign Allocations

WhenRecordActor / subjectSummary