An Audit Trail Becomes Evidence When Somebody Else Can Recompute It
Append-only is the easy half — four engineering properties separate a log file from a tamper-evident chain
Long-form write-ups of the architectural decisions behind each shipped release, what we built, why we chose one approach over another, and what happened when it met production traffic. New articles land here after the release they describe is live.
Append-only is the easy half — four engineering properties separate a log file from a tamper-evident chain
What WORM and Object Lock actually guarantee — and the gap between a backup an attacker can delete and one nobody can.
FRCP Rule 37(e) asks for reasonable steps to preserve ESI — a mailbox hold is not all of them
The thing an attacker manipulates is the policy graph — and that is what a recovery has to rebuild
Side-by-side, in-place, and the destructive revert — the blast-radius decision behind a recovery
Seven steps and two authentication events, or three and one
Why 200 tenants and a 99% accurate engineer still produce 12 wrong settings
Read operations have no blast radius. Write operations are not reversible by the person who caused them
The covered list is marketing. The not-covered list is where your restore fails
An 8-hour window on a 200-seat tenant is roughly 8,000 unrecoverable messages
A failed restore raises a ticket. A successful unauthorised one raises nothing at all
Three of the four cannot be answered from anybody's marketing page
A 500-seat client at 8% churn carries 280 departed users by year seven
The vendor is not party to your storage contract, which is the whole point
Model the offboarding case, not the growth case
Four numbers, no spreadsheet, no call to the vendor
Any vendor claiming both should be asked which one they implemented
Sixty clients, forty-five seconds a switch, about 190 hours a year
Which is why seat drift only ever moves one direction on your P&L
A fair reading of what Microsoft shipped, and the five limits it states itself
Five ATT&CK techniques in one installer, and none of them malicious
Why hash rules are a maintenance trap and signing is the way out
Deleting shadow copies is a ransomware signature. Backups touch VSS constantly.
A practical sequence for NinjaOne, Intune or GPO across a real estate
What a morning of primary-source research actually turned up
The sanction depends on what the court finds about your intent
Your directory does not get bigger when a client hires twenty people
And the one thing neither licence tier does