Tutorial
Sooner or later someone will ask: who approved this masking policy, which version built the dataset in UAT last March, and how do we know the masking worked? Audit evidence is the answer — a durable record of decisions and actions, plus proof of what each dataset contained and how it was checked.
Good evidence is produced automatically as a by-product of the work, not reconstructed from memory before an audit.
Text description
- DataNivra Cloud: Event 1 (hash h1) → Event 2 (prev h1) → Event 3 (prev h2) → Verify chain
Connection: Evidence references: URI + checksum
- Your environment: Certification report → Dataset manifest → Checksums
Why it matters
Privacy and governance programmes rely on demonstrating control, not just exercising it. Without evidence, a well-run test data process looks the same to an auditor as a careless one. Evidence also matters operationally: when a defect is traced to test data, teams need to know exactly which dataset version, policy version and source snapshot were involved. And evidence must itself be trustworthy. A log that anyone can quietly edit proves little, and evidence files that contain sensitive values create a new risk wherever they are stored.
Text description
- Gates (all must pass) (Your environment): Coverage → Masking verified → Referential integrity → Schema match → Quality rules → Provenance & checksums
Connection: Fail closed
- Outcome: All pass → certified, provisionable → Any fail → blocked, never provisioned
Example
A synthetic trail for one dataset version:
| Event | Actor | Details (metadata only) |
|---|---|---|
| Policy v7 approved | data owner (synthetic user u-17) | masking policy id, version, checksum |
| Dataset requested | tester u-42 | entity, target environment QA-2, retention 30 days |
| Job completed | agent ag-03 | row counts, duration, report checksum |
| Dataset certified | agent ag-03 | six gates passed, evidence reference |
| Dataset provisioned | agent ag-03 | target QA-2, version 12 |
Each event stores the hash of the previous one, so removing or editing an event breaks the chain. The certification report itself is a file in the customer's evidence store; the trail holds its location and checksum.
How DataNivra approaches it
The control plane keeps an append-only, hash-chained audit trail of privileged actions: approvals, requests, role changes, agent enrolment and revocation, job outcomes. Anyone with the right permission can verify the chain.
Certification reports, dataset manifests and checksums are generated by the agent and stored in your environment. The control plane stores only evidence references — a URI inside your boundary plus a checksum — so you can prove which file belongs to which dataset version without the evidence ever leaving home. Because every dataset is versioned like a data product, evidence lines up with the lifecycle.
See Dataset certification and the architecture overview.
Key takeaways
- Generate evidence as part of the pipeline, not after the fact.
- Chain audit events so tampering is detectable.
- Keep evidence files in your environment and share references and checksums.