compliance infrastructure for AI systems

6. Compliance Infrastructure: Audit Trails, Policy-as-Code, and the Append-Only Principle

TL;DR We had an AuditLogger that wrote to Loki only — the audit_events Postgres table sat empty for weeks. We had OPA running on a static policy…