Skip to main content

Audit trail

Every change, upload, classification override, export, reveal, match, purge and administrative action is appended to the audit trail. Entries can't be edited or deleted: the database role the Workbench runs as can add entries but has no permission to change or remove them.

There are two views of it:

  • Engagement → Audit trail (leads and administrators): every change, export and access to names and emails on this engagement.
  • Admin → Audit trail (administrators): the Platform audit trail, every engagement's trail plus user and cache administration, newest first, with an Engagement column (client and engagement name). The Show drop-down filters it to one action, or Every action.
The Platform audit trail with the Show filter set to Every action: entries for Revealed names & emails and Purged personal data, each with a salmon dot, then Changed user, Closed engagement, Finished classification, Uploaded rows, Created staff list and others, with the engagement and details for each.
The platform audit trail. Salmon dots mark the entries that used or destroyed names and emails.

Reading an entry​

Column
WhenDate and time, for example 2 October 2026, 09:41.
WhoThe person's email, or System for automatic actions such as the nightly retention purge.
WhatThe action (see below). A salmon dot marks a personal-data action; the key under the table reads names and emails used or destroyed.
EngagementPlatform view only.
DetailsThe recorded details, for example Purpose: Explorer: view names for the rows shown · Count: 250. Details never contain names or emails of the client's staff.

Entries are listed newest first, 100 at a time (1–100 of N): Newer and Older page through them.

Actions​

Action shownRecorded when
Created client / Updated clientA client is added or changed.
Created engagement / Updated engagementAn engagement is created or its settings saved (with how many staff lists were rescored when the industry pack changed), or its report wording saved (recorded as updated or cleared; the wording itself isn't copied into the trail).
Closed engagement / Reopened engagementLifecycle changes.
Purged personal data ●A manual or automatic purge (reason: manual or retention).
Deleted engagementAn administrator deletes an engagement.
Added team member / Changed team member / Removed team memberTeam changes, with role and PII access.
Created staff list / Uploaded rows / Finished classificationThe upload pipeline.
Changed assumptionsAssumptions saved (the staff list is rescored).
Renamed staff list / Deleted staff listStaff list changes.
Rescored with new reference dataA staff list moved onto another reference data version (From and To).
Set classification override / Removed classification overrideOverrides, with the rationale and how many staff lists were rescored (Staff lists rescored).
Uploaded names & emails ●Identities stored at upload.
Revealed names & emails ●Names decrypted, with the purpose and count.
Matched a people list ●Emails matched against the encrypted index, with the purpose.
ExportedAny export, with its format and deliverable.
Saved Copilot plan / Deleted Copilot planRollout plans.
Generated AI textAn executive summary, value-chain map or "Ask" answer, with the prompt version.
Added user / Changed userUser administration.
Verified cache entry / Deleted cache entryCache administration.
Started a reference data draft / Saved the reference data draft / Discarded a reference data draft / Published reference dataReference data administration, with notes.
Started a prompt draft / Saved a prompt draft / Discarded a prompt draft / Published a prompt / Tested a promptPrompt Lab activity, including whether a test was a preview only and the model used.

● marks personal-data actions.

Using the trail​

  • A client asks who accessed their people's names: open the engagement's Audit trail and look for the salmon-dot entries.
  • Before restoring the database from a backup: list the purges made since the restore point (Purged personal data entries on Admin → Audit trail), because the restore rolls the audit trail back too, and those engagements must be purged again afterwards. See the developer guide's runbooks.
  • Audit entries survive an engagement's purge.