Use when
- The product must support security investigations, compliance review, legal discovery, privileged-action review, or enterprise governance.
- Records must outlive ordinary UI state and personal notification cleanup.
- Retention policy, access scope, redaction, export, API retrieval, SIEM streaming, or evidence package behavior matters.
- Reviewers need to prove which actor or system changed a protected object, when, from where, and with what result.