Traceability and compliance
What gets recorded
Everything that touches a document leaves a trail, and that works in your favour.
Almost everything that happens around a document is recorded: who uploaded it, who opened it, who approved it, who downloaded it and when. It sounds like surveillance and it is not: it is what makes it possible to answer questions that would otherwise be one person's word against another's.
What is recorded
| Moment | What is kept |
|---|---|
| Upload | Who and when |
| Send | To whom, on which channel, whether it arrived and whether it was opened |
| Approval or rejection | Who decided, when and with what reason |
| Download or view | Who accessed it and when |
| Change to a value | The old value, the new one and who changed it |
What it is for, in practice
- Closing a "you never told us" with a date rather than an argument.
- Showing an auditor that the control was genuinely applied, not merely written down.
- Knowing who can answer a question about a two-year-old case.
Important
The log cannot be edited, not even by an administrator. That is what gives it value: a log someone could retouch would prove nothing, because whoever would retouch it is precisely who has the motive.
Watch out
Recording who downloads what also protects you: if one day a document leaves where it should not, the question has an answer.
Worth knowing
None of this has to be switched on: it exists from day one. The only decision is how long it is kept, which follows your policy.
›Can anyone erase their trail?
No.
›Can everyone see the log?
No, only administrators. It is sensitive information about people on the team.
›Is a third party's activity recorded?
Yes: when they opened their link, what they delivered and when they signed.
A real case
The situation
Nobody remembers who approved a certificate that turned out to be expired.
What you do
- The case log is checked
What you get
It shows who approved it and when; the criterion is fixed instead of blame being guessed at.
The situation
Nobody knows what is recorded for each action.
What you do
- Checks the log of a real case
What you get
You know what you have.
The situation
Something is asserted that the log does not support.
What you do
- Checks first what is on record
What you get
You assert what can be demonstrated.
The situation
A client asks what is stored about their activity.
What you do
- Explains which fields make up the log
What you get
The answer is specific and verifiable.
The situation
A specific action is hunted in the history.
What you do
- Filters by date, user or file
What you get
It is found without walking the whole thing.
The situation
There is concern the log could be altered.
What you do
- Verifies that entries cannot be edited
What you get
The value lies in nobody being able to correct it.
This article answers
- which actions are recorded
- is it stored who opens a document
- is there a log of what i do
- am i being monitored on the platform