01 · Mental model
Use separate records for delivery, authority, and diagnosis
Typed artifacts carry domain results between workflow stages. The run journal records authoritative transitions, approvals, denials, material decisions, and artifact references. Observability traces explain latency, model calls, tool spans, scores, and errors.
These records should correlate but not collapse into one unbounded log. Separating them improves retention, access control, privacy, incident response, and the ability to prove which record is authoritative for which question.
02 · Visual explanation
03 · Compare and decide
Choose the authoritative record
| Decision lens | Record | Answers |
|---|---|---|
| Artifact | What did the specialist produce? | Structured finding, query, diagram, plan, or decision proposal |
| Journal | What was allowed, denied, approved, or changed? | Authoritative workflow and control history |
| Trace | Why was a run slow, costly, or incorrect? | Model, tool, span, score, and error diagnostics |
| SIEM event | Does this require security correlation or response? | Minimal normalized security signal and incident context |
04 · Cybersecurity example
Investigating an unexpected finding
A final report contains a high-severity recommendation that a reviewer did not expect.
The artifact shows the finding schema and evidence IDs.
The journal shows who accepted the severity and when.
The trace reveals the model and retrieved inputs used.
The source evidence is rechecked without exposing unrelated prompts.
Outcome: The team can diagnose reasoning while preserving an authoritative approval history.
05 · What to remember
The 60-second recall
Do not use observability as the only audit record.
Typed artifacts make specialist handoffs testable.
Correlation IDs connect evidence while access and retention remain separate.
Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.
06 · Questions people ask
FAQ
07 · Primary sources