Audit log
For an ISO 27001 or SOC 2 evidence tool, an immutable record of who changed which score when is not a feature. It is the product.
What is recorded
- Every access change — grants written, modified and revoked, with the actor and the scope.
- Every elevated action — anything performed with administrator rights.
- Score changes, including manual overrides and who made them.
- Configuration changes — methodologies, layouts, stages, fields, factors.
- Structural changes — organisation unit moves, with their effective dates and reasons.
Each entry carries the actor, the timestamp, the object affected and, where relevant, the before and after values.
Reading it
Filter by actor, date range, object type or action. Elevated actions can be isolated in one click, which is usually the first thing an auditor asks to see.
Exporting
Export a filtered view for an audit or an evidence pack. Exports carry the filter that produced them, so the recipient can see what was and was not included.
What the log guarantees, and what it does not
The log is append-only: an administrator can read it and cannot edit it through the application.
Said plainly, because a security reviewer will ask: that is a promise made by software. On any platform with an administrator, “cannot” means “the application provides no way to”. Provable independence — the kind an external auditor accepts without qualification — needs a write-once destination outside the application.
We would rather state this than overclaim it, and we recommend you state it the same way in a tender response.
Retention
Audit entries are retained for the life of the workspace and survive register deletion, because the record of a decision must outlive the object the decision was about.