Guides · accountability

Audit trails: which information actually explains a change?

A useful log explains who changed what, when, in which context, why and on the basis of which document, without copying secrets or excessive personal data into logs.

Author: WM Administrator by Brillnet product team · · Reviewed by: Brillnet C-Team — operational and security review · · Updated:

Context matters as much as the action

Record the workspace, role, resource, operation identifier and execution channel. A message saying only ‘record updated’ cannot reconstruct the decision.

Separate the event from sensitive data

The log should store safe identifiers, the scope of the change and an evidence hash. Passwords, tokens, full documents and excessive personal data do not belong in logs.

Corrections must preserve chronology

Do not delete the original event after an error. Add a correction linked to the original, author, reason and approval where policy requires it.

Evidence must be exportable

An audit report should remain readable outside the system, include its time range and filters, and allow completeness checks without access to runtime secrets.

Sources and scope

For information only. This is not legal, tax or accounting advice; adapt the procedure to the documents and circumstances of the specific housing community.