SOX-shaped audit trails: what the auditor actually wants
You're not a team of one anymore. Engineering logs aren't audit trails. Auditors want six things: who, what, when, why-allowed, what-changed-as-a-result, and signed proof of immutability. The gap between 'we have logs' and 'we have an audit trail' is wider than most teams realize.