Zum Hauptinhalt springen
DocumentMS

Glossary

Audit trail

Also called: audit log, activity log

An audit trail is an append-only record of every action taken on a document — views, downloads, edits, approvals, permission changes and deletions — with the acting user, timestamp and affected version. Its value depends entirely on nobody being able to edit it.

Audit trail explained

The question that tests an audit trail

Ask whether an administrator can edit or delete entries. Anything other than a flat no means the trail cannot evidence administrator behaviour — which is exactly the behaviour an investigation is most interested in. A log that privileged users can tidy proves nothing about privileged users.

Why reads matter as much as writes

Many systems log modifications and call it an audit trail. That is sufficient for change control and useless for confidentiality. When a document appears somewhere it should not have, the question is who read it, and a change log cannot answer that.

Logging reads produces a lot of entries. That is the cost of being able to answer the question.

What a useful entry contains

The acting user by name, a server-side timestamp, the action type, the affected document and the specific version it applied to. Version-level precision matters because the useful question is rarely "was this approved" but "was the version in use at that date the approved one".

Retention of the trail itself

The audit trail should outlive the documents it describes. Questions about a disposal usually arrive after the disposal, and a trail deleted alongside the record cannot answer them. Under FDA 21 CFR Part 11 this is explicit: audit trails must be retained at least as long as the records they concern.

Regulatory context

Recorded access is a technical safeguard under the HIPAA Security Rule, evidence for Annex A logging controls under ISO 27001, and — where non-rewriteable storage is not used — part of the audit-trail arrangement SEC Rule 17a-4 permits.

FAQ

Audit trail: common questions

Does an audit trail slow the system down?

Writing entries is cheap; storing and indexing them at volume is the real cost, and it is modest relative to storing the documents themselves. Any perceptible slowdown from audit logging is an implementation problem rather than an inherent one.

Can we export the audit trail as evidence?

You should be able to, filtered by document, folder, user, action type or date range — an audit sample is normally 'everything that happened to these documents between these dates'. Exporting should itself be a logged action.

Eine 30-minütige Sitzung mit einem Solutions Engineer, mit einer Ordnerstruktur und Freigabekette, die Ihren ähneln — kein allgemeiner Demo-Mandant.