Skip to main content

3tears-agent-audit

Unified audit envelope + fire-and-forget publish helper for the 3tears platform.

Purpose

Single AuditEvent envelope + single publish_audit helper used by every domain (workspace, rbac, memory, custom tools) so the audit pipeline is one subject tree, one consumer, one table, one admin query API. Replaces domain-specific envelopes (WorkspaceAuditEnvelope, RbacAuditEnvelope) that produced slightly-different wire shapes per domain and made cross-domain audit queries require a UNION.

The package is pure Python with no NATS consumer code and no Postgres code. Publish is the only direction: a consumer-side audit consumer owns persistence to the audit events table.

Public API

from threetears.agent.audit import AuditEvent, publish_audit
  • AuditEvent -- pydantic BaseModel with extra='forbid', timezone-aware timestamp validator, closed event_type string family (dotted verb, e.g. workspace.fs_write, rbac.assignment.create). All common identity fields are typed columns on the envelope; event-type-specific extras live in details: dict[str, Any].
  • publish_audit(event, nats_client, namespace) -- fire-and-forget async helper. Serializes the envelope via model_dump_json() and awaits one nats_client.publish on {namespace}.audit.{event_type}. On any publish failure logs at WARN and returns; never raises.

Design commitments

  • Fire-and-forget. Audit publish failures must never break the producing call. The helper catches every exception, logs at WARN, and returns.
  • Typed wire contract. extra='forbid' + timezone-aware validator catch publisher-side drift at construction time, not at the consumer's decode.
  • No domain-specific envelope types. Every domain publishes the same model; event_type conveys the domain.
  • No dual-emit. There is no legacy envelope the consumer still accepts in parallel. Emission sites migrate in the same PR that deletes the legacy envelope module.

Subject naming

{namespace}.audit.{event_type} where event_type is the dotted event name (e.g. {namespace}.audit.workspace.fs_write). The consumer subscribes to {namespace}.audit.> so new event types route automatically without consumer-side changes.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

3tears_agent_audit-0.23.9.tar.gz (13.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

3tears_agent_audit-0.23.9-py3-none-any.whl (10.7 kB view details)

Uploaded Python 3

File details

Details for the file 3tears_agent_audit-0.23.9.tar.gz.

File metadata

  • Download URL: 3tears_agent_audit-0.23.9.tar.gz
  • Upload date:
  • Size: 13.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for 3tears_agent_audit-0.23.9.tar.gz
Algorithm Hash digest
SHA256 a566e16976b2156caf729e785b3e7226ba97ee25ff1d0867f2ed34037a64a88c
MD5 1b3f92a46d78dba48cdb29fcaf63b4f8
BLAKE2b-256 593180f7ca8597ebe35494f930efcfc7510ba214e8520dd69c65055eaf7dea3b

See more details on using hashes here.

Provenance

The following attestation bundles were made for 3tears_agent_audit-0.23.9.tar.gz:

Publisher: release.yml on pacepace/3tears

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file 3tears_agent_audit-0.23.9-py3-none-any.whl.

File metadata

File hashes

Hashes for 3tears_agent_audit-0.23.9-py3-none-any.whl
Algorithm Hash digest
SHA256 ba1a8e2be64d67bca87a2a7bfc2f71ece90342d2556a7f0cb77456944d1698d5
MD5 6c5ed72ffe29725ff6c89d6daa6d8881
BLAKE2b-256 2f365a1e512af43c8d9fd4cf9f80ba9a731fc590b0787e7fd027931c0f57c97b

See more details on using hashes here.

Provenance

The following attestation bundles were made for 3tears_agent_audit-0.23.9-py3-none-any.whl:

Publisher: release.yml on pacepace/3tears

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.42.0

2 files

0.41.4

2 files

0.41.3

2 files

0.41.2

2 files

0.41.1

2 files

0.41.0

2 files

0.40.0

2 files

0.39.0

2 files

0.38.0

2 files

0.37.0

2 files

0.36.0

2 files

0.35.1

2 files

0.35.0

2 files

0.34.0

2 files

0.33.0

2 files

0.32.1

2 files

0.32.0

2 files

0.31.0

2 files

0.30.1

2 files

0.30.0

2 files

0.29.0

2 files

0.28.0

2 files

0.27.0

2 files

0.26.1

2 files

0.26.0

2 files

0.25.0

2 files

0.24.7

2 files

0.24.6

2 files

0.24.5

2 files

0.24.4

2 files

0.24.3

2 files

0.24.2

2 files

0.24.1

2 files

0.24.0

2 files

0.23.11

2 files

0.23.10

2 files

This release

0.23.9 This release

2 files

0.23.8

2 files

0.23.7

2 files

0.23.6

2 files

0.23.5

2 files

0.23.3

2 files

0.23.2

2 files

0.23.1

2 files

0.23.0

2 files

0.22.5

2 files

0.22.4

2 files

0.22.3

2 files

0.22.2

2 files

0.22.1

2 files

0.22.0

2 files

0.21.0

2 files

0.20.0

2 files

0.19.4

2 files

0.19.3

2 files

0.19.2

2 files

0.19.1

2 files

0.19.0

2 files

0.18.0

2 files

0.17.9

2 files

0.17.8

2 files

0.17.7

2 files

0.17.6

2 files

0.17.5

2 files

0.17.4

2 files

0.17.3

2 files

0.17.2

2 files

0.17.1

2 files

0.17.0

2 files

0.16.1

2 files

0.16.0

2 files

0.15.0

2 files

0.14.1

2 files

0.14.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page