What each review records
Every assessment produces one evidence bundle. The bundle names the repository, the exact head and base commits, and the environment snapshot or the reason none was available.
It also lists the models and their versions, and digests of the review rules in force. Each deterministic check appears with its result, and each finding with the evidence it cites.
Append-only history
Database triggers reject any update to a finding or an evidence bundle, and the identity of a review cannot change. Triggers protect gate decisions and overrides the same way.
A rerun creates a new review beside the old one. A fix marks a finding resolved through a new record, so the original finding and its evidence stay as they were.
Who decided what
When someone dismisses a finding, confirms it, marks it fixed, or accepts the risk, Proofline records the person and the decision. The gate history shows each pull request head, the policy it ran under, and any merge that bypassed a blocked gate.
The audit log records configuration changes, such as review settings, roles, and model keys.
Questions
Can someone edit a code review result after it is recorded?
No. Proofline's database rejects updates to findings and evidence bundles. A new review records a new result beside the old one.
How long does Proofline keep review records?
Proofline keeps reviews, findings, evidence bundles, and the audit log with no expiry. It keeps model transcripts, which can contain source code, for 30 days by default, and an administrator can shorten that.
Does Proofline record gate overrides?
Yes. The gate history records a GitHub merge that bypassed a blocked gate, and the audit log records an approval given from Slack.