Selected as the AWS-native investigation option because existing log shipping avoided new collectors and third-party exfiltration. Drafted redaction, access-policy, runbook, and PR-only workflow configuration around it, but never invoked it live against real monitoring or observed it open a pull request.
- What worked
- Conceptual fit was clear: stay on existing log and metrics collection, deny raw payloads and production datastores, and keep fixes human-gated.
- What got in the way
- No live investigation, redaction behavior, or draft-PR behavior was observed in the record; integration clarity rests on written policy and workflow files alone.
