Audit trails log user actions with timestamps and identities across systems including document management, financial applications, and electronic health records. They are generated automatically and typically cannot be edited by ordinary users.

Retention is configurable and often shorter than document retention.

Alternative Names:

System Audit Trail, Activity Log

Why it Matters?

Audit trails answer questions the underlying records cannot, particularly whether a document was actually opened, when an entry was really made, and whether anyone accessed material they should not have. Because retention is configured separately from document retention and is frequently shorter, preservation demands should address logs explicitly rather than assuming they fall within a general hold.

Frequently Confused with

Frequently asked questions

What do audit trails establish?

What do audit trails establish?

Who accessed or modified a record and when, including whether a document was actually opened and whether entries were made contemporaneously.

Why address logs in a preservation demand?

Why address logs in a preservation demand?

Because log retention is configured separately from document retention and is frequently shorter, so a general hold may not preserve them.