A Provisioning Record You Can Actually Trust
The problem
- When an auditor asks you to prove a log was not edited after the fact, a plain log file is not a good enough answer — and infrastructure templates need to be provably what they claim to be, not just named that way.
The solution
- Every provisioning and deployment action is recorded in a tamper-evident log with an off-site copy; the four built-in Biomes ship pre-verified at release, with cosign signing and SBOM generation for a custom Biome you author on the roadmap, not yet enforced.
Outcomes
- Log integrity can be verified on demand, not just assumed.
- A report for any date range is one command away, ready for a compliance review.
- Every action is tied to a specific, authenticated person or role — never anonymous.