Auditing who changed what

Audit questions arrive after something has already gone wrong. A leave balance is not what it was. A project status changed. Nobody remembers doing it, and everyone is sure it was not them.

A record looks wrong. The disagreement is not about the current value; it is about how it got there.

Without a trail this ends in a conversation where the most confident person wins.

The activity log records changes with field-level before and after values, so the question has a factual answer.

The answer comes in one line: who changed the record, which field, from what value to what, and when. That settles almost every dispute about a leave balance, a status or an assignment.

Why one record instead of two

Audit is the join seen from underneath. Leave balances, project statuses, device assignments and profile fields all change in the same log. A question about any of them is answered in one place.

What is switched on

Activity log
Field-level diffs, such as a status moving from draft to submitted, with who and when.
Activity log
Filters by user, entity and action, plus quick filters for creates, updates and deletes.
Roles and permissions
Who can read the log is a permission, and the log is sensitive by nature.
Directory
Every entry points at a person, which is how a trail becomes an answer.
Support desk
Most audit questions arrive as a ticket first.

What the week looks like

  1. The question

    Somebody reports a record that does not match their expectation.

  2. First look

    Filter the log by that entity. The relevant change is usually in the first few entries.

  3. Reading it

    The entry carries the before and after values, so intent is separate from effect.

  4. If unclear

    Filter by user or by action type. Deletes are their own quick filter for a reason.

  5. Answering

    Reply with the change, the person and the timestamp rather than a theory.

  6. Ongoing

    Top-level counts show today's activity and the most active entity, which is a rough health signal.

Questions people ask

Which records does the log cover?

Changes across the product: people, projects, checklists, timesheets and more. Each update names the field with its old and new value.

Who can read the log?

Whoever holds the permission. The log shows changes across every module, so most companies keep it to a short list of admins.

Can we filter the log to deletions only?

Yes. Creates, updates and deletes are quick filters, alongside filters by user, entity and date range. Deletions are usually the first thing worth checking.