Every recorded change is time-stamped
The audit trail lives on each entity's Activity Log tab; it's per-entity, not a single global page
The log is read-only; it reflects history and can't be edited
Documents and policies additionally carry full version history
System logs are retained for at least 12 months
Where the audit trail lives
The audit trail is the Activity Log tab on each entity. There is no organisation-wide audit page; each entity carries its own trail:
An incident's Activity Log shows every change to that incident
A control's Activity Log shows every change to that control
A risk assessment's Activity Log shows every assessment update
A task's Activity Log shows status and assignment changes
A document's Activity Log shows version changes, sign-offs, and approvals
Each entity is its own source of truth for its history. To review the trail for something, open the record and switch to its Activity Log tab.
What is recorded
For each change, the trail records:
What changed: the specific field, status, or value
Who changed it: the user, or System for automated changes
When: the timestamp
From and To: the previous and new values, where applicable
Why: the comment or reason, if one was supplied
For approvals (reviews, sign-offs, evidence submissions), the trail also captures the reviewer's decision, comments, and timestamp.
End-to-end traceability
Because each stage of the compliance lifecycle carries its own log, you can follow a thread from one end to the other:
Identification → Assessment: a hazard's first appearance through to its rating
Assessment → Controls: the controls assigned to mitigate it
Controls → Records: the records (documents and policies) added for each control
Records → Review: the approval of that record
Review → Governance: its inclusion in a board report
For a regulator, this proves continuous management rather than a point-in-time effort, which is exactly what you reference when compiling an evidence pack. See Compiling an evidence pack for a regulator.
Version history
Documents and policies carry full version history in addition to their Activity Log:
Every approved version is retained
The current version is what counts as evidence
Prior versions stay accessible for audit purposes
For a document or policy, the Version History tab shows every version with its submitter, approval date, and content.
Retention
System logs are retained for at least 12 months. Customer data retention follows your contract terms: for most customers, at least the duration of the subscription plus an offboarding window.
