
An audit trail is a set of evidence preserved for later examination: who acted, when, on which object, what they did, and how the state changed. Its value is more than simply “keeping a record”. It allows an outcome to be reconnected to the process that produced it.
Suppose a crucial sentence disappears from a shared document. The final version alone cannot show whether this was an accidental deletion, an ordinary revision or an unauthorised change. If the system retains the editor, time, before-and-after content and version relationship, participants can reconstruct the event and decide whether to restore, explain or attribute responsibility.
An audit trail is not the same as ordinary browsing history. History assists recall; an audit trail is organised around completeness and verifiability of evidence. Nor is it access control: permissions restrict action beforehand, while an audit trail explains what actually happened afterwards. My judgement is that an important system should rely neither on trust alone nor on prohibition alone. It should also leave traces sufficient for accountability, without collecting more personal information than that purpose requires.
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.