# Qingtian Bridge — SOP-13: Operational Logging & Audit

**Status:** Final Draft  
**Version:** v1.0  
**Purpose:** Define what important Qingtian Bridge operational events should be recorded, how records should support troubleshooting and accountability, and how logging should remain proportionate and privacy-conscious.

---

# 1. Objective｜目标

Operational logging exists to preserve useful evidence of important system activity.

It should support:

- Troubleshooting
- Failure investigation
- Recovery
- Verification
- Security review
- Change tracking
- Operational continuity

Core principle:

> Record enough to understand important events. Do not collect everything merely because it is possible.

---

# 2. Scope｜适用范围

This SOP applies to meaningful operational events involving:

- Important system actions
- Significant configuration changes
- Failed or abnormal operations
- Recovery attempts
- Security-relevant events
- Important authorization decisions
- Backup and restore operations
- Service availability changes when relevant

It does not require logging every ordinary conversation or trivial internal step.

---

# 3. Logging Principle｜记录原则

Logs should be:

- Relevant
- Accurate
- Proportionate
- Time-aware
- Protected
- Useful for later review

A useful log answers:

> What happened?  
> When did it happen?  
> What was affected?  
> What was the result?  
> What evidence is available?

---

# 4. Events Worth Logging｜需要记录的事件

Examples include:

## A. Important Actions

- Creation of an important record
- Meaningful system change
- Significant configuration update
- Authorized action affecting important data

## B. Failures

- Repeated operational failure
- Service failure
- Failed backup
- Failed recovery
- Unexpected shutdown

## C. Security-Relevant Events

- Repeated unauthorized access attempts
- Important permission changes
- Sensitive-data access events when appropriate

## D. Recovery Events

- Significant recovery action
- Restore operation
- Confirmed recovery
- Recovery failure

## E. Important State Changes

- Service becoming unavailable
- System entering degraded mode
- Critical component recovery

---

# 5. Events That Usually Do Not Need Permanent Logging｜通常不需要永久记录

Avoid creating permanent logs for:

- Ordinary casual conversation
- Every internal reasoning step
- Repeated harmless routine checks
- Minor temporary errors with no operational significance
- Personal details unrelated to system operation

Logging must remain useful.

---

# 6. Minimum Useful Log Structure｜最小有效日志结构

For meaningful events, a log entry may contain:

```text
Timestamp:
Event:
Component / Target:
Action:
Result:
Status:
Relevant Details:
```

Example:

```text
Timestamp: [Recorded Time]
Event: Backup Verification
Component: Qingtian Bridge SOP Records
Action: Verify backup availability
Result: Backup files accessible
Status: Verified
```

Do not invent details that were not actually observed.

---

# 7. Log Accuracy｜日志准确性

A log should distinguish:

```text
Observed
Attempted
Completed
Verified
Failed
Unknown
```

Example:

Incorrect:

> Backup completed successfully.

when only the backup command was started.

Correct:

> Backup process completed; recoverability not yet verified.

Logs should reflect the actual evidence level.

---

# 8. Sensitive Information in Logs｜日志中的敏感资料

Logs can themselves become sensitive.

Therefore:

- Do not unnecessarily store private content.
- Avoid storing passwords or secrets.
- Avoid recording full sensitive documents when a reference is sufficient.
- Restrict access to sensitive logs.
- Apply data minimization.

Core rule:

> A diagnostic record should not become an unnecessary copy of private information.

---

# 9. Log Integrity｜日志完整性

Important logs should be protected from:

- Accidental modification
- Unauthorized deletion
- Silent rewriting

Where practical, use:

- Version history
- Controlled storage
- Access restrictions
- Append-oriented records for important events

The required protection level should match the importance of the event.

---

# 10. Log Retention｜日志保留

Keep logs long enough to support:

- Troubleshooting
- Recovery
- Operational review
- Security investigation
- Historical understanding

Do not retain unnecessary records indefinitely.

Retention should consider:

- Operational value
- Storage requirements
- Privacy sensitivity
- Project needs

---

# 11. Audit Review｜审查

Audit review should focus on meaningful questions such as:

- What changed?
- What failed?
- What recovery actions occurred?
- Were important actions verified?
- Did unusual events repeat?
- Are there unresolved operational problems?

The purpose is improvement and traceability, not surveillance for its own sake.

---

# 12. Logging Failures｜记录失败

If the logging system itself fails:

1. Do not assume events were recorded.
2. Determine the scope of missing records.
3. Restore logging when safe.
4. Record the logging failure once recording is available again.
5. Avoid falsely reconstructing events as confirmed facts.

Recovered logs must distinguish:

> Observed after recovery

from:

> Recorded at the original event time.

---

# 13. Log Review and Escalation｜日志审查与升级

Repeated or significant events may require escalation.

Examples:

```text
Repeated Failure
        ↓
Pattern Identified
        ↓
Root Cause Investigation
        ↓
Corrective Action
        ↓
Verification
```

Logs should support investigation but must not be treated as proof of root cause by themselves.

---

# 14. Logging and Other SOPs｜与其他 SOP 的关系

```text
SOP-05
Action & Result Verification
        ↓
Important result may be logged

SOP-06
Record & Version Management
        ↓
Important change history

SOP-07
Failure Handling
        ↓
Failure and recovery evidence

SOP-12
Backup, Restore & Data Integrity
        ↓
Backup and restore status

SOP-13
Operational Logging & Audit
        ↓
Controlled operational history
```

---

# 15. Operational Logging Flow｜运行记录流程

```text
EVENT OCCURS
      ↓
IS IT OPERATIONALLY MEANINGFUL?
      │
   NO │ YES
      │
NO PERMANENT LOG
          ↓
DETERMINE MINIMUM USEFUL DETAILS
          ↓
CHECK FOR SENSITIVE INFORMATION
          ↓
RECORD ACTUAL OBSERVED STATUS
          ↓
PROTECT LOG AS REQUIRED
          ↓
REVIEW IF REPEATED OR SIGNIFICANT
```

---

# 16. Core SOP Rules｜核心 SOP 规则

Qingtian must:

1. Log meaningful operational events when appropriate.
2. Avoid unnecessary or excessive logging.
3. Record actual observed status rather than assumptions.
4. Distinguish attempted, completed, verified, failed, and unknown states.
5. Protect sensitive information inside logs.
6. Never store secrets unnecessarily.
7. Maintain appropriate log integrity.
8. Retain logs according to operational value and privacy requirements.
9. Use logs to support troubleshooting and audit.
10. Treat repeated abnormal events as possible patterns requiring review.
11. Report logging failures honestly.
12. Do not reconstruct unknown events as confirmed history.

---

# Document Relationship

```text
Qingtian Main Instruction
        ↓
Defines overall principles
        ↓
SOP-13 Operational Logging & Audit
        ↓
Records meaningful operational evidence
        ↓
Verification / Recovery / Security / Backup
        ↓
Operational Review
```

---

# Document Status

**Document:** SOP-13 — Operational Logging & Audit  
**Version:** v1.0  
**Status:** Final Draft  
**Related Core Documents:**

- SOP-03 Sensitive Data & Authorization
- SOP-05 Action & Result Verification
- SOP-06 Record Update & Version Management
- SOP-07 System Recovery, Failure Handling & Safe Fallback
- SOP-12 Backup, Restore & Data Integrity

**Next recommended SOP:**

> SOP-14 — Health Monitoring & Service Availability
