Append-only, and what that actually means
The audit trail records every action taken on every document and cannot be edited from the application — not by a user, not by an administrator, not through the API. Entries are added, never amended or removed. That property is the whole value: a log an administrator can tidy is a log that proves nothing about administrator behaviour, which is exactly the behaviour an auditor is most interested in.
Each entry carries the acting user, the timestamp, the source IP address, the action, the affected document and the specific version it applied to. Version-level precision is what lets you answer the question auditors actually ask, which is not "was this approved" but "was the version in use at that date the approved one".
