# Appendix A: Trace event schema

> The event types and fields in a session's trace file.

From *How to Own Intelligence* by Mac Anderson. Canonical page: https://macanderson.com/research/how-to-own-intelligence/trace-event-schema

Each session is one JSON Lines file. Each line is one event. Every event carries `v` (schema version), `session_id`, `ts` (ISO 8601, UTC), and `type`.

```text
session_start
  cwd, base_commit, remote_url_hash, model, harness, harness_version, source,
  task_id, config_hash

message
  turn, role (user | assistant), text_redacted, text_hash, truncated (bool)

tool_call
  turn, tool_name, tool_use_id, input_redacted, input_hash,
  output_redacted, output_hash, truncated (bool), duration_ms

oracle_verdict
  attempt, mode (baseline | grade), verdict (PASS | FAIL | ERROR),
  tests_hash, image_digest, diff_hash, oracle_host, signature (optional)

session_end
  outcome (flipped | no_flip | no_task | aborted), attempts,
  final_diff_hash, reason (from the harness), ended_at
```

Rules: `text_redacted`, `input_redacted`, and `output_redacted` are the only fields that ever hold content, and they hold it after redaction. The `_hash` fields are SHA-256 of the unredacted value, so a later pass can tell whether two truncated values were the same without storing them. `remote_url_hash` rather than the URL, because remote URLs sometimes carry credentials. The verdict's `signature` is over the canonical JSON of the other verdict fields, with the oracle host's key.
