Straza / conversation capture

capture:
Conversation capture pipeline Prompts and reply deltas from a governed session pass a policy capture gate with three modes: off, verbatim, redact. Captured turns are hashed in full, optionally redacted, size-capped, spooled, drained to strazad, published as audit events, mirrored into the conversation store, witnessed by the hash chain, and readable in the Transcripts screen with substring or locally-hashed-value search. governed session prompts + replies banner: session is captured prompt.submit reply · session.end capture gate PolicySet capture: block mode: off redact wins across sets no event emitted captured turn hash FULL original SHA-256, before redact/cap the chain witnesses everything redact masked on the client mode recorded per turn size cap truncated: true + full-content hash audit spool JSONL · async rotates on drain drain /v1/audit/batch detached · rebound outbox → JetStream straza.audit.{prompt,reply} events rev 5 · additive conversation_turns durable consumer · retention 720 h hash chain witness sha256(prev ‖ ce) Transcripts screen substring search · hashed-value search value hashed locally; plaintext never travels verbatim is deliberate (leak hunting needs real content), so the operator gates the read model and keeps its retention short
Capture is off unless a matched PolicySet enables it. Flip the gate to verbatim or redact, then send a prompt through the pipeline. Hover any node for its facts.
What this shows

Policy-controlled conversation capture. The client captures prompts at prompt.submit and reply deltas from the harness transcript at session.end. The gate is the PolicySet capture: block (policyset rev 2): off unless a matched set enables it, redact wins across sets, verbatim is the default mode when enabled. Captured sessions are told, with a banner and a one-liner in the session context. Every captured turn is hashed in full (SHA-256) before any redaction or size cap, so the hash chain witnesses even what it did not store and a known-leaked value remains findable. Turns ride the normal audit lane (JSONL spool, detached drain to /v1/audit/batch, transactional outbox, JetStream subjects straza.audit.prompt and straza.audit.reply), then a durable consumer mirrors them into conversation_turns with its own retention knob (governance.captureRetention, default 720 h), while the chain writer links them tamper-evidently. The Transcripts screen and strazactl search by substring or by a value hashed locally in the browser/CLI, so the plaintext of a hunted secret never travels.