Audit trails log user actions with timestamps and identities across systems including document management, financial applications, and electronic health records. They are generated automatically and typically cannot be edited by ordinary users.
Retention is configurable and often shorter than document retention.
Alternative Names:
System Audit Trail, Activity Log
Why it Matters?
Audit trails answer questions the underlying records cannot, particularly whether a document was actually opened, when an entry was really made, and whether anyone accessed material they should not have. Because retention is configured separately from document retention and is frequently shorter, preservation demands should address logs explicitly rather than assuming they fall within a general hold.
Frequently Confused with
Related terms
Frequently asked questions
What do audit trails establish?
Why address logs in a preservation demand?





