# Turn IBeam Auditing On Deliberately

Points out that service auditing records nothing until a host switches it on.

Follow these project instructions.
# Turn IBeam Auditing On Deliberately

Points out that service auditing records nothing until a host switches it on.

Version: `1.0.0`

Service auditing is off until you turn it on. The option that enables it defaults to false, and select auditing has its own flag that is false as well. Everything else about auditing - capturing before and after state, choosing which operations are covered - only takes effect once auditing is enabled at all.

This matters because the code reads as though it is working. Attributes are in place, the executor is wired, the sinks are registered, and not one record is written. The gap usually surfaces during an incident, which is the worst moment to discover the history is empty.

Turn it on in configuration, deliberately, and then decide what to exclude rather than what to include: default to auditing writes, then switch off the operations that are noisy or that carry data you should not keep.

Confirm it with a record, not with configuration. Perform one audited operation in a real environment and read the entry back. A configuration value that looks right in a settings file is not evidence that a sink received anything.

#### Constraints
- Do not enable capture of before and after state for operations holding data you must not retain.
- Never assume an audit trail exists because attributes and sinks are in place.

#### Verification
- Auditing is enabled explicitly in configuration for every environment that needs it
- One real operation was performed and its audit record read back
- Operations excluded from auditing were excluded on purpose, and the reason is written down
