Gough for Compliance & Audit

A record of every provisioning and deployment action that cannot be quietly edited after the fact, with a copy kept off-site — ready to hand to an auditor.

Pain points

  • Auditors need proof a log wasn’t edited after the fact, not just a log.
  • Provisioning actions performed outside a documented process are hard to reconstruct later.
  • Signed artifacts need to be provable, not just claimed.

How Gough helps

  • Every action is logged in a way that can be verified on demand, mirrored to a separate location, and exported as a report for any date range. (Hash-Chained Audit Trail)
  • The four built-in Biomes ship pre-verified at release, so infrastructure changes built on them carry the provenance auditors expect; cosign signing and SBOM generation for a custom Biome you author is on the roadmap, not yet enforced. (Biomes: Packaged, Versioned Workloads)
  • Every action is tied to a specific, authenticated person or role, so the audit trail is attributable — never anonymous. (Vault PKI + SPIFFE/SPIRE Identity)

Read the audit chain docs