DocuTwin audit boundary
DocuTwin Denied Execution Audit Boundary
The denied execution audit boundary is metadata-only and explicitly excludes request bodies, patient identifiers, clinical free text, and connector payloads until execution-attempt, persistence, and privacy models are approved.
Evidence headers
/api/workflows/governed-execution/docutwin-draft-note-review
Capture policy
persistence-decision-required
Durable audit storage, retention policy, access review, execution-attempt idempotency, and incident response ownership must be approved before governed execution moves beyond deny-by-default.
request body
Excluded from denied execution audit metadata until an approved privacy and persistence model exists.
patient identifiers
Excluded from denied execution audit metadata until an approved privacy and persistence model exists.
clinical free text
Excluded from denied execution audit metadata until an approved privacy and persistence model exists.
production connector payloads
Excluded from denied execution audit metadata until an approved privacy and persistence model exists.
authentication secrets
Excluded from denied execution audit metadata until an approved privacy and persistence model exists.
payment or insurance member identifiers
Excluded from denied execution audit metadata until an approved privacy and persistence model exists.