Audit alerts, evidence, retention and legal holds

Tell the right people about sensitive changes, seal and verify the audit trail, set how long it is kept and place legal holds.

Required permission: audit.view, audit.manage

Before you begin

Every sensitive change is written to an audit trail that nobody can edit. The Audit menu under Administration lets you act on it. You need audit.view to read; audit.manage to seal, set retention, place holds and change alert rules. Without audit.view the Audit menu entries are hidden.

Tell people about sensitive changes (alert rules)

  1. Go to Administration > Audit > Alert rules and click New rule.
  2. Type a Name. Empty gives 'Name the rule.'
  3. In Actions, list what raises the alert. Use an exact action or a prefix ending in . or *. You can list 1 to 50 patterns. The default is partner.bank, account., tax., role.*. Empty gives 'List the actions that raise it...'.
  4. Tick Who is told. Every recipient must hold audit.view, otherwise: 'Each recipient must be a member who may read the audit trail (audit.view).'
  5. Leave Active on, and save. Untick it to pause the rule.

When someone changes, say, a customer's bank details, the people you named see an alert in Administration > Audit > Sensitive-change alerts. The alert shows who, what and which fields changed, never the values. The person who made the change is not alerted about their own change. Click Mark all read to clear the New badges.

Seal and verify the trail

Sealing groups events into a signed batch with a fingerprint. Verifying checks the whole trail against those seals.

  1. Go to Administration > Audit > Audit evidence.
  2. Click Seal new events (audit.manage). Events newer than about 60 seconds wait for the next seal. You see 'N event(s) sealed.' or 'Nothing new to seal.'
  3. Click Verify the trail (audit.view). The result reads, for example, 'Verified: 120 sealed event(s) intact, 0 removal(s) explained, 3 not yet sealed.'

Seal regularly, for example at month end, and keep the verification result with your close file.

Set how long the trail is kept

  1. Go to Administration > Audit > Retention and legal holds.
  2. Set Keep the audit trail (years) between 5 and 50. The default is 7. A lower number gives 'Keep the audit trail 5 to 50 years (GCC VAT records need at least five).'
  3. Click Save retention. The version number goes up.

A hold protects matching events from disposal while an inquiry or case is open.

  1. On the same screen, click Place a hold.
  2. Type a Name, for example Tax inquiry 2026, and Why (the inquiry, case or letter). Empty gives 'Name the hold and say what it is for.'
  3. Optionally narrow it: Actions starting with (for example partner.), Only this record id, and a From and To date. Leave everything empty to hold all actions. Check that To is not before From; the screen does not check it.
  4. Save.

To release a hold, another administrator clicks Release and types a reason ('Say why the hold ends.'). The person who placed it cannot release it: 'Somebody other than the person who placed it releases a hold.'

Dispose of old events (two people)

Events older than the retention period, and not under a hold, may be removed.

  1. Administrator A clicks Propose disposal.
  2. Administrator B opens it and clicks Approve or Reject, with a reason.
  3. If approved, the events are removed and the state shows done. Verify the trail then reports them as explained removals. Events under a hold are kept and counted as Kept by holds.

The proposer cannot approve: 'Somebody other than the person who proposed it approves a disposal.' A rejected disposal removes nothing.

What happens next

Alerts reach people as they happen. Seals and holds are permanent records of their own. A database administrator cannot edit audit rows either: the database refuses with 'The audit trail is append-only...'.

Good to know

  • Not every screen change is an alert. Only the actions in your active rules raise one.
  • A hold is the only way to stop disposal; retention alone does not.