Audit ledger
Ankayma records connection-level facts — which run, which identity, which service was reached, who was invited or removed — as signed, append-only ledger entries. It is tamper-evident: the history can’t be altered without breaking the chain.
Need-to-know applies: a regular member sees only their own receipts, not the whole tenant. A dedicated AuditViewer role will surface the raw ledger. Receipts you already hold today — deploy and SSH — are entries in this same ledger.