Guides · accountability
Audit trails: which information actually explains a change?
A useful log explains who changed what, when, in which context, why and on the basis of which document, without copying secrets or excessive personal data into logs.
Author: WM Administrator by Brillnet product team · · Reviewed by: Brillnet C-Team — operational and security review · · Updated:
Context matters as much as the action
Record the workspace, role, resource, operation identifier and execution channel. A message saying only ‘record updated’ cannot reconstruct the decision.
Separate the event from sensitive data
The log should store safe identifiers, the scope of the change and an evidence hash. Passwords, tokens, full documents and excessive personal data do not belong in logs.
Corrections must preserve chronology
Do not delete the original event after an error. Add a correction linked to the original, author, reason and approval where policy requires it.
Evidence must be exportable
An audit report should remain readable outside the system, include its time range and filters, and allow completeness checks without access to runtime secrets.
Sources and scope
For information only. This is not legal, tax or accounting advice; adapt the procedure to the documents and circumstances of the specific housing community.