The audit-export endpoint mints a signed PDF and a review-ready Excel workbook covering the evidence your workspace produced. This page describes the scope across the Evidence Pilot, Regulated Team, and Enterprise paths, plus the verification procedure outside counsel or a regulator can run on receipt.
The short version: this is a signed export of recorded workspace evidence. The PDF is built for receipt verification; the Excel workbook is built for review and traceability.
The export covers records that were recorded in the selected window. It does not add events that were never recorded, or records outside that window. Start with the sample walkthrough →
Your workspace tier controls which of the five named event categories can appear. See the tier matrix → Read the category definitions →
Included records carry the signed and file-integrity details described in the verification section. For a concrete example, follow the sample decision, chain and reviewer note examples.
Sign in to choose one of your owned models. The workbook includes its existing evidence summary and canonical links back to the EvalRecord, drift, alert, access-control, and reviewer sign-off pages.
The pricing tier you select at sign-up drives the workspace's tiercolumn, which the export route checks at request time. The matrix below is what outside counsel and a regulator can expect to see in the resulting export: ✓ means the category is folded into the signed payload, — means the category is not surfaceable from this tier.
| Marketing tier | Seat band | Eval runs | Drift-ledger entries | Reviewer notes | Sign-offs | Hash-chain anchors |
|---|---|---|---|---|---|---|
| Evidence Pilot | 1 workflow · 1 model · 30 days | |||||
| Regulated Team | Team workspace | |||||
| Enterprise | Multi-team deployment |
The Evidence Pilot produces a focused replayable package for one workflow and one model. Regulated Team carries the ongoing signed evidence trail, including drift and reviewer context. Enterprise adds the full procurement-ready export surface and buyer-defined retention window and category set per engagement.
Every category surfaces as one export line-item per record in the window, plus a chain-anchor row that links the record back to its position in the hash chain. The canonical JSON view folds everyper-kind column below — adding or removing one record of any family shifts the content hash.
The PDF is server-side rendered by the renderDocumentPdf helper exported from the pdf module (pure pdf-lib, no network egress, no native deps, serverless-safe). The DocumentSpec it consumes is built by the user-owned buildAdminAuditExportDocumentSpec helper in src/lib/business/admin-audit-export.ts, so the same SHA-256 fold covers the line items, the meta rows, and the footer.
hash = sha256Hex( canonicalJson( { start, end, events } ) )
fingerprint = sha256( BETTER_AUTH_SECRET ).slice( 0, 16 )
signature = sha256Hex( hash + ":" + fingerprint )
fileHash = sha256Hex( renderedPdfBytes )
# PDF footer line (printed on every page of the export)
hash: <hash>
signature: <signature>
file-hash: <fileHash>
fingerprint-id: <first-12 hex chars of fingerprint>
# Verification (no secret required)
1. Read all events the export route returned for the (start, end) window.
2. Build { start, end, events } sorted by ISO timestamp, canonical-JSON it.
3. sha256 the canonical-JSON bytes → recover the content hash.
4. sha256( contentHash + ":" + fingerprint ) → recover the signature.
5. sha256 the downloaded PDF bytes → must equal the file-hash on the footer
AND the X-PDF-SHA256 response header.events.reverse() produces the same hash bytes.sha256(BETTER_AUTH_SECRET).slice(0, 16) — sixteen hex characters of the deployment's session signing secret. Per-deployment stable by construction: two deployments holding different signing secrets produce different signatures for the same window, so a signature cannot be replayed across environments.X-PDF-SHA256 response header carrying sha256(PDF bytes) AND prints the same value on a footer line of every PDF page. A downloader can verify with sha256sum workspace-audit-*.pdf against the header — a bit-for-bit integrity check independent of the signed hash above.hash even after the signing material rotates. The PDF file hash is unaffected by any signing rotation — it is a property of the rendered bytes alone.Review the Evidence Pilot or send us your outside-counsel brief directly. We'll scope the right PDF or Excel pack for your next review.