Self-Service vs. Override: Where the Audit Trail Lives

Spend Request within limit over limit Self-Service Path Auto-approved against soft allocation Logged automatically as usage Structured log entry: usage event, no approval needed Override Path Authenticated CLI / API call only Identity + scope checked before anything happens Structured audit log entry: who, resource, old/new limit, timestamp, required justification No email link exists on either path — nothing to forward, screenshot, or replay.

Both paths end in a structured, queryable log. Only the override path requires proving who you are before anything changes.