4.4 Audit outputs
;
When you pass a non-NULL audit, the check reports:
continuous_audit— the OR of the alarm masks of anySYSTEM_AUDITACEs that matched, i.e. what a continuous-audit consumer would log for this access.staging_mismatch—1if evaluating the staged central access policy would have produced a different result than the active one. This is the signal you watch when rolling out a central access policy change: a non-zero value means the pending policy would decide this access differently.