Compliance frameworks care less about your vulnerability counts than about your control environment: who can change security behavior, how changes happen, and whether you can reconstruct them later. That is exactly the record most AppSec stacks do not keep — because the operations are scattered across vendor consoles, YAML history, and chat messages.
The questions an auditor will ask
- Who disabled scanning on this pipeline, when, and under what justification?
- What was the enforcement policy on the date of this release?
- Who rotated this provider credential, and what did it grant?
- Which bulk operations touched these fifty pipelines last quarter?
- Can any of this be shown per tenant, without exposing other tenants?
Why git history and vendor logs are not enough
YAML history shows file edits, not intent or authorization. Vendor audit logs cover that vendor's surface only, in that vendor's format, with that vendor's retention. Neither joins the story across your estate, and neither records the operations that happened in scripts and consoles in between.
Operational history as a first-class model
Kangl writes every consequential operation — provider connection changes, credential rotations, Security Runtime settings, pipeline enable/disable, bulk actions, policy changes, sync and repair runs — into a durable, tenant-scoped audit history with actor, target, and correlation ID. Evidence becomes a query, not a quarter-end scramble.

