Your assurance report covers a twelve-month observation window ending 31 March. In February the assessor asks for the pipeline record of every production deploy in that window. CI build logs are kept 90 days and the cloud audit trail 90 days. What do you fix?
Show the full answer Hide the answer
What is being tested
Whether you can tell the difference between an operational log and a piece of evidence. A period-based assurance opinion is a statement about every day in the window, so the evidence has to survive the whole window plus the time it takes to write the report. Nine of your twelve months are already unrecoverable, and no amount of goodwill at the assessor's end changes that.
The mechanism
Operational logs are sized for debugging. A 90-day retention is a sensible default for build output, because the value of a build log falls to nearly nothing a week after the build. Control evidence has the opposite decay curve: it is worthless until somebody asks, and then it is the only thing that matters, two to fifteen months later.
The two also differ in size by orders of magnitude. The deploy record an assessor needs is a few hundred bytes of structured fields: change id, commit, approver identity, which checks ran, their results, the artefact digest, the target environment and the timestamp. The build log around it is megabytes of compiler output. Pay retention on the hundred bytes, not the megabytes. A separate append-only sink, written by the pipeline as it runs, with its own retention of the longest window plus report lag plus one cycle, is both cheaper and stronger: nothing in it was assembled by a human after the fact.
Why the other options fail
- Extend retention to 400 days. This works and it buys the wrong thing. Retaining 200 GB a month of build output for 400 days instead of 90 is roughly a 4.5x increase in that store to preserve a small structured subset, and retention applies to everything in it, including committer identities, request bodies captured in test failures and whatever customer data leaked into a fixture. You have created a data minimisation problem to solve an evidence problem, and you still have no evidence for the nine months already gone.
- Narrow the sample to 90 days. The period is the product. A window-based opinion that only tested the final quarter is a different and weaker thing from what your customers compare against, and the scope section of the report will say so. It is also not the assessor's gift to give.
- Quarterly spreadsheet export. The artefact is now produced by a person, from a source that no longer exists by the time anyone checks. Completeness cannot be verified, the file is editable by whoever holds the drive, and you have reintroduced the manual evidence pack you were trying to remove.
When this is the wrong answer
If the engagement is a point-in-time assessment rather than a period opinion, current state is the evidence and a separate historical store is overhead. And if the control runs entirely inside a managed service whose own audit trail is already immutable and retained long enough, emit nothing extra: point at theirs. The rule is to own the evidence pipeline only for controls your own systems operate in production, and to set its retention from the longest window anyone will ever assess rather than from what the debugging tools happen to keep.