- Help centre
- Access and security
Concept
The audit trail
Every change, and every view of confidential material, is written down with who, what and when, in a record no one can edit.
What is recorded
Each entry names who acted, from which address and device, what they did, the record it touched and its matter, what the record looked like before and after, and the reason where one was given. It is written in the same step as the change itself, so a change that could not be recorded does not happen.
Opening confidential material is recorded too: a document's views and downloads have their own access log, and searches record what they showed.
Why it can be trusted
- The system has no way to change or delete an entry: the database refuses it.
- Each entry carries a fingerprint of the one before it. A check runs every night, and an entry altered outside the system breaks the chain and raises a critical alert.
- Entries are kept for at least seven years and never purged automatically.
That makes the trail the record of processing a data controller keeps under the Data Protection Act, 2012 (Act 843), and the firm's answer to "who saw this file".
Read and export it
- Open Settings, then Audit log.
- Narrow by person, record, action, matter and dates.
- Open an entry to see the before and after side by side.
- Export what you have narrowed to. The export is itself recorded.

Each matter also has its own Activity tab, read from the same trail, so its history is one stream judged by the same rules as the matter.
Was this helpful?
Read next
- Ethical wallsA wall makes a matter or a client invisible to the people it shuts out, everywhere in the system, until two people agree to lift it.
- The emergency overrideFor the rare moment someone must act beyond their permissions, the override opens access for four hours, with a reason, a second sign in and a notice.
- Data subject requestsLog, verify, locate and answer a request under the Data Protection Act, 2012 (Act 843), within the firm's time, with every step on the record.
