Policy-controlled conversation capture. The client captures prompts at prompt.submit and reply deltas from the harness transcript at session.end. The gate is the PolicySet capture: block (policyset rev 2): off unless a matched set enables it, redact wins across sets, verbatim is the default mode when enabled. Captured sessions are told, with a banner and a one-liner in the session context. Every captured turn is hashed in full (SHA-256) before any redaction or size cap, so the hash chain witnesses even what it did not store and a known-leaked value remains findable. Turns ride the normal audit lane (JSONL spool, detached drain to /v1/audit/batch, transactional outbox, JetStream subjects straza.audit.prompt and straza.audit.reply), then a durable consumer mirrors them into conversation_turns with its own retention knob (governance.captureRetention, default 720 h), while the chain writer links them tamper-evidently. The Transcripts screen and strazactl search by substring or by a value hashed locally in the browser/CLI, so the plaintext of a hunted secret never travels.