Skip to main content

3tears-agent-audit

Unified audit envelope + fire-and-forget publish helper for the 3tears platform.

Purpose

Single AuditEvent envelope + single publish_audit helper used by every domain (workspace, rbac, memory, custom tools) so the audit pipeline is one subject tree, one consumer, one table, one admin query API. Replaces domain-specific envelopes (WorkspaceAuditEnvelope, RbacAuditEnvelope) that produced slightly-different wire shapes per domain and made cross-domain audit queries require a UNION.

The package is pure Python with no NATS consumer code and no Postgres code. Publish is the only direction: a consumer-side audit consumer owns persistence to the audit events table.

Public API

from threetears.agent.audit import AuditEvent, publish_audit
  • AuditEvent -- pydantic BaseModel with extra='forbid', timezone-aware timestamp validator, closed event_type string family (dotted verb, e.g. workspace.fs_write, rbac.assignment.create). All common identity fields are typed columns on the envelope; event-type-specific extras live in details: dict[str, Any].
  • publish_audit(event, nats_client, namespace) -- fire-and-forget async helper. Serializes the envelope via model_dump_json() and awaits one nats_client.publish on {namespace}.audit.{event_type}. On any publish failure logs at WARN and returns; never raises.

Design commitments

  • Fire-and-forget. Audit publish failures must never break the producing call. The helper catches every exception, logs at WARN, and returns.
  • Typed wire contract. extra='forbid' + timezone-aware validator catch publisher-side drift at construction time, not at the consumer's decode.
  • No domain-specific envelope types. Every domain publishes the same model; event_type conveys the domain.
  • No dual-emit. There is no legacy envelope the consumer still accepts in parallel. Emission sites migrate in the same PR that deletes the legacy envelope module.

Subject naming

{namespace}.audit.{event_type} where event_type is the dotted event name (e.g. {namespace}.audit.workspace.fs_write). The consumer subscribes to {namespace}.audit.> so new event types route automatically without consumer-side changes.

Release files for 3tears-agent-audit 0.52.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for 3tears-agent-audit 0.52.1
File Size Uploaded
3tears_agent_audit-0.52.1.tar.gz 14.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for 3tears-agent-audit 0.52.1
File Interpreter ABI Platform
3tears_agent_audit-0.52.1-py3-none-any.whl Python 3 none any Details

Total release size: 24.9 kB

Release files / 3tears_agent_audit-0.52.1.tar.gz

Download URL 3tears_agent_audit-0.52.1.tar.gz
Size 14.3 kB
Tags Source
SHA-256 checksum
How to use checksums
17534c872a7faecdcfb6790c1e967104aab1931bbbf080d768f2f42a2794f5b1
BLAKE2b-256 checksum
How to use checksums
53375ba6b16d3dea0393f6116bf9784c64c21a6ecb42a46a98469d80ae40ae6a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / 3tears_agent_audit-0.52.1-py3-none-any.whl

Download URL 3tears_agent_audit-0.52.1-py3-none-any.whl
Size 10.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6ff5df711f700a12a16a4a41bc20645325a6a7ddd6965012976205599a098ac7
BLAKE2b-256 checksum
How to use checksums
826f914199ab1128efab1e5cd45112994fa60211ade2573e6c619f90ef5186cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.52.1 This release

2 release files

0.52.0

2 release files

0.51.1

2 release files

0.51.0

2 release files

0.50.0

2 release files

0.49.0

2 release files

0.48.0

2 release files

0.47.1

2 release files

0.47.0

2 release files

0.46.1

2 release files

0.46.0

2 release files

0.45.1

2 release files

0.45.0

2 release files

0.44.0

2 release files

0.43.0

2 release files

0.42.0

2 release files

0.41.4

2 release files

0.41.3

2 release files

0.41.2

2 release files

0.41.1

2 release files

0.41.0

2 release files

0.40.0

2 release files

0.39.0

2 release files

0.38.0

2 release files

0.37.0

2 release files

0.30.0

2 release files

0.29.0

2 release files

0.28.0

2 release files

0.27.0

2 release files

0.26.1

2 release files

0.26.0

2 release files

0.25.0

2 release files

0.24.7

2 release files

0.24.6

2 release files

0.24.5

2 release files

0.24.4

2 release files

0.24.3

2 release files

0.24.2

2 release files

0.24.1

2 release files

0.24.0

2 release files

0.23.9

2 release files

0.22.4

2 release files

0.22.3

2 release files

0.22.2

2 release files

0.22.1

2 release files

0.22.0

2 release files

0.21.0

2 release files

0.20.0

2 release files

0.19.4

2 release files

0.19.3

2 release files

0.19.2

2 release files

0.19.1

2 release files

0.19.0

2 release files

0.18.0

2 release files

0.17.9

2 release files

0.17.8

2 release files

0.17.7

2 release files

0.17.6

2 release files

0.17.5

2 release files

0.17.4

2 release files

0.17.3

2 release files

0.17.2

2 release files

0.17.1

2 release files

0.17.0

2 release files

0.16.1

2 release files

0.16.0

2 release files

0.15.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page