What is an audit trail?

An audit trail is a chronological, tamper-resistant record of every action taken on a document or in a system: who viewed it, who shared or downloaded it, who changed its status, and when each of those things happened.

What it actually means

An audit trail answers the question “who did what, and when.” For a document, that means a running log that captures each meaningful interaction: the views, the shares, the downloads, the changes to retention or holds. It is the difference between saying “I believe the right people handled this correctly” and showing exactly who accessed a document and under what authority.

A good audit trail is created automatically, as a byproduct of normal use, rather than something anyone has to maintain. If keeping the log depends on people remembering to record their actions, it is not an audit trail. It is a wish.

Why it matters

For records that carry consequences, an audit trail is what makes handling defensible. When an auditor asks how a confidential file was accessed, when a board wants assurance that sensitive materials stayed protected, or when a donor’s family asks whether a fund was managed properly, the audit trail turns a stressful question into a straightforward answer backed by evidence.

It also deters mishandling. People treat records more carefully when they know that access is recorded. An audit trail is both a record after the fact and a quiet incentive before it.

What it should capture

At minimum, a document audit trail should log views, shares, downloads, and governance actions like changes to retention or the placing of a legal hold, each with the person and the timestamp, so the full history of a document’s handling can be reconstructed on demand.

PaperlessZen™ records every view, share, and download automatically. See governance and security. Related terms: legal hold, system of record.