Security Taxonomy
Claustrum separates security-relevant audit traffic from general operational audit traffic.
Security Action Scope
Security stream includes:
auth.*access.*api_key.*raw.searchraw.viewaudit.exportoidc.*github.permissions.*security.*
Category Mapping
auth.*,oidc.*→authaccess.*,github.permissions.*,security.*→accessraw.search,raw.view,audit.export→dataapi_key.*→config
Severity Mapping
Default severity:
high:api_key.*,audit.export,security.*, auth failures/revokesmedium:auth.*,access.*,raw.search,raw.view,oidc.*,github.permissions.*low: fallback
audit_logs.target may explicitly override:
{
"category": "auth",
"severity": "high"
}
Workspace Controls
workspace_settings:
security_stream_enabled(defaulttrue)security_stream_sink_id(optional dedicated sink)security_stream_min_severity(low|medium|high, defaultmedium)
If no dedicated sink is set, Claustrum falls back to enabled security-capable sinks.