Hardware, platform and safety / Security and privacy
What goes wrong with “Removal audit chain” in a shop, considering someone who recomputes the whole chain can rewrite history?
Built in the repository (checked files or tested library code; not a product you can run yet) C0201
Each removal decision is written to a local log in which every entry commits to the previous one, and the current state is cross-checked against the chain. It is tamper-evident, not tamper-proof; publishing the head hash outside the computer (for example in a printed or exported record) is a planned mitigation. Plan for: someone who recomputes the whole chain can rewrite history; no trusted time offline; local only. It exists only as a file in the repository, not as a product feature.
How to read this
The tag above says how real the answer is. Answers describe the plan in the repository and design documents. No app is released. Where an answer touches tax or law, treat it as a theme to verify with a qualified local adviser.