Modules
Audit platform for Elixir teams using Phoenix, Ecto, and PostgreSQL.
Audited write-path helper — one call for transaction-local actor GUC, domain
writes, optional semantic action linkage, and audit_transaction_id on success.
Ecto schema for the audit_changes table.
Ecto schema for the audit_transactions table.
Pure projection of a single captured row change into deterministic, JSON-friendly maps.
Brownfield cutover helpers for honest T₀ semantics with Threadline capture.
Public create/read boundary for Threadline-owned evidence records.
Reusable proof projection for Threadline evidence viewer surfaces.
Closed subject inventory for Threadline-owned evidence records.
CSV and JSON export for audited row changes.
Executes asynchronous export jobs safely by streaming directly to disk.
Enqueues Threadline export jobs for asynchronous processing.
Enqueues Threadline exports in Oban.
Runs export jobs in supervised, in-process tasks.
Ecto schema for the threadline_evidence_records table.
Health checks for Threadline infrastructure.
One structured result from Threadline.Health.trigger_findings/1 or
Threadline.Health.legacy_key_findings/1.
Validates :expected_uncovered_tables and :audit_anyway configuration
for Threadline.Health.trigger_coverage/1's third bucket.
Soft-dependency adapter for deriving Threadline audit context from Sigra state.
Higher-level investigation helpers layered on top of Threadline query primitives.
One transaction-focused incident bundle with linked context and packaged diffs.
One bundled incident change with raw linked structs and a packaged diff.
One investigation change row with linked transaction and optional action context.
One transaction-oriented investigation slice with optional action metadata.
Helpers for propagating audit context through background job args maps.
Namespace for the Threadline operator surface — the opt-in mountable LiveView surface that turns Threadline's investigation contracts into one-click answers for documented support questions.
Authentication contract for the Threadline operator surface.
Mounts Threadline's operator interface in a Phoenix router with host-owned authorization and query scoping.
Plug that extracts AuditContext from a Plug.Conn and stores it in
conn.assigns[:audit_context].
Ecto query implementations for the Threadline public API.
One keyset page from the actor history query layer.
One keyset page from the timeline query layer.
Batched retention purge for audit_changes and empty audit_transactions.
Validates config :threadline, :retention before purge runs.
Value object representing the actor who performed an audited operation.
Ecto schema for the audit_actions table.
Execution context for an audited request or job.
Stores and retrieves export files and other persistent artifacts.
Stores Threadline exports on the local filesystem.
Stores Threadline exports in S3-compatible object storage.
Resolves and validates the PostgreSQL schema that stores Threadline-owned data.
Telemetry integration helpers for Threadline.
Pure policy for comparing Threadline.Health.trigger_coverage/1 output with
host-configured expected audited table names.
Mix Tasks
Brownfield capture cutover helper — honest T0 semantics (see guides/brownfield-continuity.md).
Shows Threadline-owned evidence proof output through one canonical viewer task.
Loads application config, starts the configured Ecto repo, and writes an export file
using Threadline.Export — no ad-hoc Ecto.Query in this task (parity with
mix threadline.retention.purge).
Generates an Ecto migration that adds audit_changes_row_history_idx to an
existing Threadline install.
Generates an Ecto migration that installs Threadline audit triggers on the specified tables.
Shows trigger coverage as reported by Threadline.Health.trigger_coverage/1,
with a three-section table (default) or JSON output (--json).
Loads application config, starts the configured Ecto repo, and fetches the incident bundle for a given transaction ID.
Generates an Ecto migration file for the Threadline audit schema.
Shows configured versus deployed redaction policy drift for Threadline capture triggers through the same report shape used by the operator surface.
Delegates to Threadline.Retention.purge/1 after loading application config and
starting the configured Ecto repo (same resolution pattern as mix threadline.verify_coverage).
Verifies that tables listed in application config have Threadline audit
triggers installed, using the same catalog queries as Threadline.Health.trigger_coverage/1.