Evidence

Set audit retention

How long you keep decision records is a decision in itself, and the plugin treats shortening it as consequential.

  • Activity & evidence
  • 4 min read

The bounds

Time
7 to 365 days.
Events
1,000 to 1,000,000.
Default
Retention is opt-in. Until you set it, records are not pruned on a schedule.

Both bounds apply together. Whichever limit is reached first governs.

Shortening is gated

Extending retention is routine and applies immediately. Shortening requires explicit confirmation, because it destroys evidence — and that should never happen as a side effect of adjusting a setting or accepting a default.

Pruned events cannot be recovered

Export first if there is any chance you will need the window you are about to drop. See Export evidence for review.

Choosing a value

  • Start longer than feels necessary. The cost is database rows; the cost of the alternative is an incident you cannot reconstruct.
  • Match any obligation you already have. If your organisation keeps operational logs for a period, match it.
  • Consider request volume. A busy agent can reach an event ceiling long before a day ceiling.
  • Revisit after a month of real traffic, when you know your actual rate.

Retention and the chain

Pruning removes old events by design, so the chain covers the retained window. This is expected and is not a verification failure — a failure means the retained record is inconsistent, which is a different thing entirely.

Activity & evidence

Keep the boundary while you fix the problem.

A good fix restores intended behaviour without creating a second path around WordPress or the governed request lifecycle.