The audit log
What is recorded, what it is for, and the two questions it answers that nothing else can.
The audit log records what was done, by whom, and when. It is not a version history of every field — it is a record of the actions that matter if someone later asks.
What it is genuinely for
- "Who exported this?" Every export is logged, which is the whole reason export is a permission of its own.
- "Who changed this record?" Correction is a right patients have; attribution is what keeps a corrected record trustworthy.
A record that anyone can change is not evidence. A record that anyone can change and that says who changed it is. The log is what makes editing safe rather than dangerous.
Leavers stay in it
Removing a member revokes their access; it does not erase their history. A log that forgets who did something when they change jobs is not a log.
When to read it
Almost never, which is the point. It is for the day a patient disputes a record, an insurer asks how a figure was reached, or you need to establish that a bulk deletion was one person on one afternoon.
The one proactive use: after a leaver's last day, check whether they exported anything in their final week. It takes a minute and it is the question you cannot answer retrospectively if you never look.
Common questions
- Can the log be edited?
- No. An editable audit log answers no question worth asking.
- Does it record who viewed a record?
- It records actions, with exports called out specifically. Logging every read produces a volume nobody ever reads back.