---
id: KB-TZ-001
url: https://app.codecontract.io/help/traceability-and-compliance/who-did-what-and-when
idioma: en
categoria: trazabilidad
audiencia: usuario
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-CO-004, KB-SC-003, KB-CR-004, KB-TZ-021]
citadoPor: [KB-TL-009, KB-TZ-003, KB-CO-008, KB-CO-009, KB-DI-005, KB-TZ-011, KB-TZ-016, KB-CR-006, KB-CR-008, KB-AD-001, KB-IN-001, KB-MA-001, KB-IN-002, KB-TZ-002]
enLaApp: https://app.codecontract.io/settings/audit
---

# Who did what and when

_The record that turns a file into evidence, and how to show it to a third party._

**Responde a:** who did what and when on the platform · audit log · how do I prove what happened to a document · public verification of a document · how long are documents retained

The difference between a shared folder and this platform is not where the files live: it is that every step is on record. Who asked for what, when the notice went out, when the link was opened, who uploaded the document, who corrected a field and who confirmed it.

**En corto**

- Every action is recorded with its author and its time.
- The record cannot be edited: if it could, it would prove nothing.
- A third party can verify a document without an account and without your permission.
- Retention is configured per organisation, according to what your sector requires.

## What gets recorded

- Sends: to whom, on which channel, at what time, and whether they bounced.
- Opens: when each link was opened, which separates "it never arrived" from "they did not look".
- Deliveries: which document, who uploaded it and from where.
- Automatic readings and manual corrections, with who confirmed each field.
- Signatures: who, when, at what level and whether they validated the code.
- Changes to the organisation's configuration.

## Why it cannot be edited

Same reasoning as in SmartCheck. A record its owner can modify proves nothing to a third party, because the other side can always claim it was changed afterwards. Immutability is what gives it value.

## How to show it to an outsider

| You need | You use |
| --- | --- |
| An auditor to check one specific document | The evidence link or public verification |
| To produce a signature in proceedings | The signed PDF and its evidence chain |
| To hand over a whole period | The exported folder dossier |
| To justify an internal action | The organisation's audit log |

> [!NOTE]
> What makes evidence strong is that someone who does not trust you can check it. That is why public verification needs neither an account nor your permission.

## How long it is kept

It depends on your organisation's retention policy, configured according to what your sector requires. If you need to keep something beyond that on your own terms, download it: a signed PDF is self-contained and validates without depending on the platform.

## Frequently asked questions

**Can I see who downloaded a document?**

Accesses are logged along with the rest of your organisation's traceability.

**What if someone on my team leaves?**

Their access is withdrawn, but what they did stays under their name. If it vanished, the history would stop being traceable.

**Does it work as evidence in legal proceedings?**

What you produce is the signed document with its evidence chain and timestamp, which a third party can verify independently.

**Can the log be exported?**

Yes. That is what you hand over in an audit, rather than walking someone through screens.

## Ejemplos

**A client claims they were never asked for a document that is missing from their file.**

- Opens the case and shows the send date and channel
- Shows the link was opened two days later
- Confirms nothing was delivered and that they were reminded twice

→ The conversation stops being about who remembers what, because the facts are dated.

**Somebody claims they reviewed something and there is no record.**

- Checks that action's log

→ What was done has an author and a time.

**A figure appears changed and nobody knows who touched it.**

- Checks the figure's own history

→ The change has a date and someone responsible.

**You want to know who granted a third party access.**

- Looks up the action in the log

→ Granting stops being anonymous.

**Two people give different accounts of what happened.**

- Checks the recorded sequence

→ The dispute closes by looking.

**An auditor asks for evidence of a control.**

- Shows the log of real operations

→ The control moves from assertion to evidence.
