Archive Enterprise audit evidence
The archive needs an optional S3 client dependency that neither the Gateway nor Flightdeck image packages. Setting these properties on a stock image does not start archival.
The Enterprise archive is off by default. Its keys are dvara.flightdeck.audit-archive.enabled, schedule (default 02:00 UTC daily), retention-days (180), grace-period-days (7), bucket, endpoint, region, access-key-id, secret-access-key, and max-rows-per-archive (1,000,000).
The job uploads a complete workspace-day before deleting it and recounts the partition to avoid deleting rows that arrived during upload. Cost and token-usage records remain for the audit retention period or 400 days, whichever is longer; 400 days is a fixed floor, not another setting. Archived token-usage records retain their credential fingerprint, so owner-only lookups by credential still find archived calls. Treat the object-store copy and its access controls as part of your evidence system.