Seal replay
Every create, patch, and delete appends an event to a per-agent hash chain. Replaying recomputes each seal from stored rows alone, so a rewritten or reordered event is detectable.
Chain definition
genesisSeal = "000000000000000000000000…"
seal_n = SHA-384( UTF-8(prevSeal) || canonicalJson(event_n) )
event_n = { seq, eventType, entityId, actor, payload, createdAt }
canonicalJson recursively sorts object keys, preserves array
order, and normalises dates to ISO-8601, so two runs on two
machines hash identical bytes.Soft-deleted agents keep their rows and audit events, so a chain shared before deletion stays verifiable.
No chains to replay
Create and patch an agent, then come back. Every mutation you make will appear here with a verdict.