# Threadline v0.11.1 - Table of Contents

Audit platform for Elixir teams using Phoenix, Ecto, and PostgreSQL

## Guides

- Overview
  - [README](readme.md)
  - [Phoenix reference application](phoenix-reference-application.md)

- Integrations
  - [Threadline ↔ Sigra integration](sigra.md)
  - [Threadline ↔ phx.gen.auth integration](phx-gen-auth.md)

- Evaluate
  - [How Threadline works](how-threadline-works.md)
  - [Code walkthrough](code-walkthrough.md)
  - [Threadline domain reference](domain-reference.md)
  - [Evaluating Threadline](evaluating-threadline.md)

- Adopt
  - [Integration Contracts](integration-contracts.md)
  - [Upgrade Path](upgrade-path.md)
  - [Upgrading to 0.11.0](upgrading-to-0-11.md)
  - [Brownfield continuity with Threadline capture](brownfield-continuity.md)
  - [Production checklist (Threadline)](production-checklist.md)
  - [Getting started with Threadline in a Phoenix SaaS app](getting-started-saas.md)
  - [Local Docker DX](local-docker-dx.md)
  - [Configuration and command reference](configuration-and-commands.md)

- Operate
  - [Performance](performance.md)
  - [Operator Surface](operator-surface.md)
  - [Threadline Incident Playbook](incident-playbook.md)
  - [Adoption evidence playbook](adoption-evidence-playbook.md)
  - [Audit table indexing cookbook](audit-indexing.md)

- Contribute
  - [Adoption pilot backlog](adoption-pilot-backlog.md)
  - [Contributing to Threadline](contributing.md)
  - [Operator surface design system](operator-surface-design-system.md)
  - [Changelog](changelog.md)

## Modules

- Core API
  - [Threadline](Threadline.md): Audit platform for Elixir teams using Phoenix, Ecto, and PostgreSQL.
  - [Threadline.Audit](Threadline.Audit.md): Audited write-path helper — one call for transaction-local actor GUC, domain
writes, optional semantic action linkage, and `audit_transaction_id` on success.
  - [Threadline.ChangeDiff](Threadline.ChangeDiff.md): Pure projection of a single captured row change into deterministic, JSON-friendly maps.
  - [Threadline.Continuity](Threadline.Continuity.md): Brownfield cutover helpers for honest **T₀** semantics with Threadline capture.
  - [Threadline.Evidence](Threadline.Evidence.md): Public create/read boundary for Threadline-owned evidence records.
  - [Threadline.Export](Threadline.Export.md): CSV and JSON export for audited row changes.
  - [Threadline.Health](Threadline.Health.md): Health checks for Threadline infrastructure.
  - [Threadline.Investigation](Threadline.Investigation.md): Higher-level investigation helpers layered on top of Threadline query primitives.
  - [Threadline.Job](Threadline.Job.md): Helpers for propagating audit context through background job `args` maps.
  - [Threadline.Plug](Threadline.Plug.md): Plug that extracts `AuditContext` from a `Plug.Conn` and stores it in
`conn.assigns[:audit_context]`.
  - [Threadline.Query](Threadline.Query.md): Ecto query implementations for the Threadline public API.
  - [Threadline.Retention](Threadline.Retention.md): Batched retention purge for `audit_changes` and empty `audit_transactions`.
  - [Threadline.Telemetry](Threadline.Telemetry.md): Telemetry integration helpers for Threadline.

- Data Types
  - [Threadline.Capture.AuditChange](Threadline.Capture.AuditChange.md): Ecto schema for the `audit_changes` table.
  - [Threadline.Capture.AuditTransaction](Threadline.Capture.AuditTransaction.md): Ecto schema for the `audit_transactions` table.
  - [Threadline.Evidence.Proof](Threadline.Evidence.Proof.md): Reusable proof projection for Threadline evidence viewer surfaces.

  - [Threadline.Evidence.Subject](Threadline.Evidence.Subject.md): Closed subject inventory for Threadline-owned evidence records.
  - [Threadline.Governance.EvidenceRecord](Threadline.Governance.EvidenceRecord.md): Ecto schema for the `threadline_evidence_records` table.
  - [Threadline.Health.Finding](Threadline.Health.Finding.md): One structured result from `Threadline.Health.trigger_findings/1`.
  - [Threadline.Investigation.IncidentBundle](Threadline.Investigation.IncidentBundle.md): One transaction-focused incident bundle with linked context and packaged diffs.

  - [Threadline.Investigation.IncidentChange](Threadline.Investigation.IncidentChange.md): One bundled incident change with raw linked structs and a packaged diff.

  - [Threadline.Investigation.LinkedChange](Threadline.Investigation.LinkedChange.md): One investigation change row with linked transaction and optional action context.

  - [Threadline.Investigation.LinkedTransaction](Threadline.Investigation.LinkedTransaction.md): One transaction-oriented investigation slice with optional action metadata.

  - [Threadline.Query.ActorHistoryPage](Threadline.Query.ActorHistoryPage.md): One keyset page from the actor history query layer.

  - [Threadline.Query.TimelinePage](Threadline.Query.TimelinePage.md): One keyset page from the timeline query layer.

  - [Threadline.Semantics.ActorRef](Threadline.Semantics.ActorRef.md): Value object representing the actor who performed an audited operation.
  - [Threadline.Semantics.AuditAction](Threadline.Semantics.AuditAction.md): Ecto schema for the `audit_actions` table.
  - [Threadline.Semantics.AuditContext](Threadline.Semantics.AuditContext.md): Execution context for an audited request or job.

- Configuration &amp; Extension Points
  - [Threadline.Export.Orchestrator](Threadline.Export.Orchestrator.md): Executes asynchronous export jobs safely by streaming directly to disk.

  - [Threadline.ExportQueue](Threadline.ExportQueue.md): Enqueues Threadline export jobs for asynchronous processing.
  - [Threadline.ExportQueue.Oban](Threadline.ExportQueue.Oban.md): Enqueues Threadline exports in Oban.
  - [Threadline.ExportQueue.TaskAdapter](Threadline.ExportQueue.TaskAdapter.md): Runs export jobs in supervised, in-process tasks.
  - [Threadline.Health.Policy](Threadline.Health.Policy.md): Validates `:expected_uncovered_tables` and `:audit_anyway` configuration
for `Threadline.Health.trigger_coverage/1`'s third bucket.
  - [Threadline.Retention.Policy](Threadline.Retention.Policy.md): Validates **`config :threadline, :retention`** before purge runs.
  - [Threadline.Storage](Threadline.Storage.md): Stores and retrieves export files and other persistent artifacts.
  - [Threadline.Storage.Local](Threadline.Storage.Local.md): Stores Threadline exports on the local filesystem.
  - [Threadline.Storage.S3](Threadline.Storage.S3.md): Stores Threadline exports in S3-compatible object storage.
  - [Threadline.StorageSchema](Threadline.StorageSchema.md): Resolves and validates the PostgreSQL schema that stores Threadline-owned data.
  - [Threadline.Verify.CoveragePolicy](Threadline.Verify.CoveragePolicy.md): Pure policy for comparing `Threadline.Health.trigger_coverage/1` output with
host-configured expected audited table names.

- Integrations
  - [Threadline.Integrations.Sigra](Threadline.Integrations.Sigra.md): Soft-dependency adapter for deriving Threadline audit context from Sigra state.

- Operator Surface
  - [Threadline.OperatorSurface](Threadline.OperatorSurface.md): Namespace for the Threadline operator surface — the opt-in mountable
LiveView surface that turns Threadline's investigation contracts into
one-click answers for documented support questions.
  - [Threadline.OperatorSurface.Auth](Threadline.OperatorSurface.Auth.md): Authentication contract for the Threadline operator surface.

  - [Threadline.OperatorSurface.Router](Threadline.OperatorSurface.Router.md): Mounts Threadline's operator interface in a Phoenix router with host-owned
authorization and query scoping.

## Mix Tasks

- Mix Tasks
  - [mix threadline.continuity](Mix.Tasks.Threadline.Continuity.md): Brownfield capture cutover helper — honest T0 semantics (see `guides/brownfield-continuity.md`).
  - [mix threadline.evidence.show](Mix.Tasks.Threadline.Evidence.Show.md): Shows Threadline-owned evidence proof output through one canonical viewer task.
  - [mix threadline.export](Mix.Tasks.Threadline.Export.md): Loads application config, starts the configured Ecto repo, and writes an export file
using `Threadline.Export` — **no** ad-hoc `Ecto.Query` in this task (parity with
`mix threadline.retention.purge`).
  - [mix threadline.gen.row_history_index](Mix.Tasks.Threadline.Gen.RowHistoryIndex.md): Generates an Ecto migration that adds `audit_changes_row_history_idx` to an
existing Threadline install.
  - [mix threadline.gen.triggers](Mix.Tasks.Threadline.Gen.Triggers.md): Generates an Ecto migration that installs Threadline audit triggers on the
specified tables.
  - [mix threadline.health.coverage](Mix.Tasks.Threadline.Health.Coverage.md): Shows trigger coverage as reported by `Threadline.Health.trigger_coverage/1`,
with a three-section table (default) or JSON output (`--json`).
  - [mix threadline.incident](Mix.Tasks.Threadline.Incident.md): Loads application config, starts the configured Ecto repo, and fetches
the incident bundle for a given transaction ID.
  - [mix threadline.install](Mix.Tasks.Threadline.Install.md): Generates an Ecto migration file for the Threadline audit schema.
  - [mix threadline.policy.show](Mix.Tasks.Threadline.Policy.Show.md): Shows configured versus deployed redaction policy drift for Threadline capture
triggers through the same report shape used by the operator surface.
  - [mix threadline.retention.purge](Mix.Tasks.Threadline.Retention.Purge.md): Delegates to `Threadline.Retention.purge/1` after loading application config and
starting the configured Ecto repo (same resolution pattern as `mix threadline.verify_coverage`).
  - [mix threadline.verify_coverage](Mix.Tasks.Threadline.VerifyCoverage.md): Verifies that tables listed in application config have Threadline audit
triggers installed, using the same catalog queries as `Threadline.Health.trigger_coverage/1`.

