DX, completeness and observability.
- Testing API: AuditLog::fake() with recording assertions
- Capture completeness: fail-open audit failures are now visible (Stats banner + nav badge)
- OTel bridge: incoming W3C traceparent captured as trace_id, with an "Open distributed trace" link to your APM
- Token/client attribution (Sanctum/Passport)
- HasAuditTrail trait for per-model access
- Legal holds: exempt a subject from retention
- Postman export of the read API