Audit log
Immutable log of who did what and when — for forensics and compliance.
Required by GDPR, SOC2, ISO 27001, HIPAA. Best practice: append-only, signed lines, separate storage (so attackers can't erase traces), automatic archival. Different from regular logging — audit follows policy, not debug.