Gough for Compliance & Audit
A record of every provisioning and deployment action that cannot be quietly edited after the fact, with a copy kept off-site — ready to hand to an auditor.
Pain points
- Auditors need proof a log wasn’t edited after the fact, not just a log.
- Provisioning actions performed outside a documented process are hard to reconstruct later.
- Signed artifacts need to be provable, not just claimed.
How Gough helps
- Every action is logged in a way that can be verified on demand, mirrored to a separate location, and exported as a report for any date range. (Hash-Chained Audit Trail)
- The four built-in Biomes ship pre-verified at release, so infrastructure changes built on them carry the provenance auditors expect; cosign signing and SBOM generation for a custom Biome you author is on the roadmap, not yet enforced. (Biomes: Packaged, Versioned Workloads)
- Every action is tied to a specific, authenticated person or role, so the audit trail is attributable — never anonymous. (Vault PKI + SPIFFE/SPIRE Identity)