The audit trail
Open Comply → Audit trail, or g then a. Every action that changes anything writes an event here, and events are never changed or removed. The database itself refuses updates and deletes on the table, so not even the owner, nor the people who built the system, can tidy the past.
What is recorded
Thirty-one kinds of event, among them:
- Signing in and out, failed sign-ins, passwords set.
- Users created, edited, enabled and disabled; roles created, changed and assigned.
- Products created and edited, and a product's class changed as an event of its own.
- Purchases created, edited, received and cancelled.
- Stock received, adjusted, quarantined, released and disposed of; a certificate of destruction recorded.
- Sales completed and voided, with the licence state at the time.
- Regulatory blocks: every refusal to create, order, receive or sell a Class A or B product.
- The licence and the shop's details recorded and changed; a licence expired by the sweep.
- Reminders raised, acknowledged and closed.
- Reports exported and sales summaries generated and sent.
Each event carries who did it, when, what it was done to, and the details that matter for that kind: the reason for a void, the quantity of an adjustment, the reference on a disposal.
Reading it
Filter by event, by the type of thing it was done to (a sale, a batch, a user) and by date. Click a row for the full detail.
Three reads worth making a habit:
- Voids, monthly. Every void has a reason; read them.
- Adjustments, monthly. Stock that goes down without a sale has a reason too.
- Regulatory blocks, whenever one appears. A block means someone tried to order, receive or sell something the shop may not; find out why.
Who may read it
Those with the view the audit trail permission: by default the owner, the practitioner and the auditor. A sales clerk cannot see it, and an auditor cannot change anything they read.