Definitions · M · Evidence & audit
Metadata-only audit
Metadata-only audit means default telemetry exports tool names, risk tiers, policy rule IDs, and lineage references — not prompt bodies or customer PII. SIEM, Slack, and compliance pack exports follow this contract unless explicitly opted in.
Metadata-only audit is Blekline's default telemetry contract: exports include tool names, risk tiers, policy rule IDs, lineage node references, and timestamps — not prompt bodies, not customer PII, not vault ciphertext.
Where it applies
| Export | Default payload |
|---|---|
Runtime log (/operations/activity) | Mask/block decision metadata |
| SIEM forward | JSON or CEF metadata fields |
| Slack high-risk alerts | Tool + tier + rule ID |
| Eval pack export | Posture summary + gap list (no secrets) |
Opt-in extensions
Raw prompt retention requires explicit workspace policy and is discouraged for production eval — see Trust boundaries.
In Blekline
- Verify in
/operations/integrationsprobe messages and/operations/complianceexport preview.