Governance release. Per-team cost attribution that AWS's own bill agrees with, redaction enforced inside the audit log rather than at its call sites, a tamper-evident hash chain across rotated segments with an archive hook, sealed recovery of redacted values to a key the gateway cannot read back, OIDC single sign-on, and per-team rate, concurrency and token limits. Also a control mapping for security review, stating what is not done as carefully as what is.