Question
Given permanently retained, operator-only security audit events for credential lifecycle transitions, retention reductions, pending-retirement retention changes, retirement requests and cancellations, successful group purge, and exceptional owner recovery, which additional actions must United audit; what exact fields, tamper-resistance, and operator query behavior must the audit log provide; and how must failed human and Terraform authentication attempts be rate-limited, logged, measured, and alerted on without exposing credentials or enabling username, group, or route enumeration?
Question
Given permanently retained, operator-only security audit events for credential lifecycle transitions, retention reductions, pending-retirement retention changes, retirement requests and cancellations, successful group purge, and exceptional owner recovery, which additional actions must United audit; what exact fields, tamper-resistance, and operator query behavior must the audit log provide; and how must failed human and Terraform authentication attempts be rate-limited, logged, measured, and alerted on without exposing credentials or enabling username, group, or route enumeration?