Audit retention should preserve accountability without turning prompts and tool payloads into a permanent shadow database. Classify evidence by purpose, sensitivity, jurisdiction, and reconstructive value.
Retention tiers
| Tier | Examples | Policy |
|---|---|---|
| Decision record | Identity, policy, action, approval, result, outcome | Durable, integrity-protected, exportable |
| Operational telemetry | Latency, tokens, retries, health, errors | Shorter operational window with aggregation |
| Sensitive content | Prompts, retrieved text, tool arguments and results | Opt-in, minimal, separately encrypted and access-controlled |
| Secrets | Bearer tokens, API keys, private credentials | Never intentionally capture; detect and purge |
Write the schedule
For every field define purpose, owner, lawful or contractual basis, default duration, deletion trigger, legal-hold behavior, storage region, access roles, and export format. Preserve hashes or immutable references when the source record may remain in its system of record.
Deletion test
Delete one user, workspace, and expired tenant in a non-production environment. Verify primary stores, search indexes, caches, analytics copies, backups, exports, and subprocessors follow the documented policy while required audit evidence remains intelligible and appropriately pseudonymized.
Apply the retention schedule to the BlueBear audit evidence contract.