Skip to content

Audit log

Last checked on

The Audit log shows who created, changed or deleted which record in this workspace, when, and the old and new values. Nobody can edit or remove an entry, not even an owner.

Why this protects your organisation

When something goes wrong, the first questions are who changed what, and when. A log that nobody can alter answers those questions reliably, including after an incident or a dispute. It also shows an auditor that changes to your management system are traceable (ISO 27001 control 8.15 asks you to keep and protect logs of activity).

Steps

  1. Open Audit log in the Workspace group.
  2. The newest entries are at the top. Click the When column to change the order.
  3. Read per entry Who did it, the Action and the Record it concerns.
  4. Check Old and new values to see exactly what changed.

Every member of the workspace can read the log, advisors included. It only shows changes to records within this workspace.

The columns

  • When: the date and time of the action.
  • Who: the person who did it, a supplier contact, or System.
  • Action: Created, Updated, Deleted, Signed in, Approved, Confirmed read, Closed, Proposal decided, Member added, Member's role changed or Member removed.
  • Record: the kind of record and its identifier.
  • Old and new values: what the fields were before and after the change.

Signed in appears when someone arrives in this workspace from another one through Switch workspace. The full log is also part of every data export.

Changes to members

Who belongs to the workspace, and in which role, decides who can see and change your evidence. Adding a member, changing their role and removing them are therefore logged too, through Members and advisers. The Record column shows the workspace itself. Old and new values show the user's name and email address, the role and, for an advisor, the modules they may edit. The name and email address stay readable even after that account is gone.

If it does not work

Who says System

The change was not made by a person, for example by a background task such as an import. When a supplier fills in a questionnaire, their name is shown followed by (supplier).

The Old and new values text is cut off

Long changes are shortened in the table. The start of the text shows which fields were involved.

I cannot delete an incorrect entry

That is deliberate. The log is read only for every role, so it can be trusted as a record. Correct the record itself instead: that correction appears as a new entry.

Screens this is about

  • Audit log

Read next