Skip to content

Add evidence-preserving finding archival and storage controls #54

Description

@MahdiHedhli

Context

The asset-centered findings sprint deliberately exempts raw events linked to findings from ordinary retention so findings never lose their supporting evidence. That preserves explainability for public beta, but storage can grow indefinitely.

Desired outcome

Give operators explicit, auditable control over long-term finding evidence without creating dangling evidence links or silently weakening a finding.

Acceptance criteria

  • Define retention tiers for open, resolved, and archived findings.
  • Preserve a sufficient immutable evidence summary before raw supporting events are compacted or removed.
  • Show projected/current storage usage and the effect of a policy change.
  • Keep lifecycle history, detector provenance, observable, timestamps, counts, outcome, and recommendation explainable after archival.
  • Make archival/compaction atomic, restart-safe, and auditable.
  • Add migration, retention, restore, and concurrent-ingestion tests.
  • Document backup and rollback behavior.

Boundary

Do not silently delete evidence supporting an open finding.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions