audit
Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
What it does
Section titled “What it does”Assembles everything codeArbiter logs — overrides.log, triage.log, decisions/,
sprint-log.md, checkpoints/ — into a single dated record: what happened during a window, who
signed off on it, and what’s still outstanding. It’s read-only over every source; its only write is
the packet itself, saved to
.codearbiter/audits/<YYYY-MM-DD>.md (a second run the same day appends -2, never overwriting).
Every override and low-confidence sprint entry is quoted verbatim, never paraphrased, and an empty
section is stated as empty — “no overrides in window” is itself part of the record.
/ca:audit "[<from-ref> <to-ref> | --since-checkpoint | --since <date>]"Two tags/SHAs bound an explicit range; --since-checkpoint runs from the last recorded checkpoint
to HEAD; --since <date> runs from an ISO date to HEAD; no argument defaults to the most recent
tag (or last checkpoint, or a hard stop asking for an explicit window if neither exists).
Example
Section titled “Example”> /ca:audit v2.4.0 v2.5.0
Window: v2.4.0..v2.5.0 (2026-06-15 to 2026-07-02)Packet written: .codearbiter/audits/2026-07-02.md
Summary: Commits: 41 (12 feat, 9 fix, 6 docs, ...) Overrides: 2 (both routine, 0 SECURITY-OVERRIDE) Open items: 1 unresolved [CONFIRM-11], 3 checkpoint findings still openWhen to reach for it
Section titled “When to reach for it”You want an evidentiary packet for a range, not a live snapshot — for that, use /ca:status. This
command only reports what reviews already found; to trigger a fresh review sweep, use
/ca:checkpoint.
Related
Section titled “Related”Source
Section titled “Source”Source — plugins/ca/commands/audit.md (v2.9.1)
---description: Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.argument-hint: "[<from-ref> <to-ref> | --since-checkpoint | --since <date>]"---
# /ca:audit — promotion packet
Everything codeArbiter logs, it logs append-only and scattered: `overrides.log`, `triage.log`,`decisions/`, `sprint-log.md`, `checkpoints/`. This command assembles them into the one document ateam lead, compliance reviewer, or auditor actually asks for: *what happened in this window, whoauthorized it, and what is still open.* Read-only over every source; its only write is the packet.
## Window
- `<from-ref> <to-ref>` — two tags/SHAs (e.g. `v1.2.0 v1.3.0`).- `--since-checkpoint` — from the `last-checkpoint` record to HEAD.- `--since <date>` — ISO date to HEAD.- No argument → from the most recent tag to HEAD (no tags → last checkpoint; neither → BLOCK and ask for an explicit window).
## Flow
1. Resolve the window to a commit range and a time range; both appear in the packet header.2. Gather, citing each source file: - **Commits** — `git log` over the range, grouped by Conventional-Commit type; merge commits listed with their PR reference. - **Overrides** — every `overrides.log` line in the time range, verbatim (including `SECURITY-OVERRIDE` and `DEV:` entries), each with its `BY:` identity. - **Triage** — every small-lane classification in `triage.log` in range. - **Decisions** — ADRs created or superseded in range (from `decisions/` file dates and the supersede chains), each with its Decided-by attribution. - **Sprint auto-decisions** — entries from `sprint-log.md` in range; list every `low`-confidence entry verbatim, count the `high` ones. - **Open questions** — all currently-unresolved `[CONFIRM-NN]` items. - **Checkpoint findings** — from the most recent `checkpoints/*.md`: findings still open.3. Write the packet to `${CLAUDE_PROJECT_DIR}/.codearbiter/audits/<YYYY-MM-DD>.md` (second run the same day appends `-2`, `-3`, … — an existing packet is never overwritten). Surface the path and a three-line summary: commits, overrides, open items.
## Hard gate
Read-only over every source — MUST NOT modify any log, decision, or checkpoint while assembling.MUST NOT overwrite an existing packet. MUST quote override and low-confidence sprint entriesverbatim — never paraphrase an audit line. An empty section is stated as empty, never omitted —"no overrides in window" is itself the finding.
## When NOT to use
- Live project state right now → `/ca:status`.- Triggering reviews → `/ca:checkpoint` (this command only reports what reviews already found).