The audit trail
An append-only, hash-chained record of what people, agents and machines did, which you can check without trusting the platform.
Every approval, enrolment, task hand-off and policy change the platform makes, and every action a workbench or node reports for its agents, is one row in the organisation's audit trail. The trail is built so you can rely on it.
Why you can trust it
It is append-only. The database refuses to change or delete an audit row, and the platform has no way to.
It is a hash chain. Each row is numbered and carries a SHA-256 hash of its own content together with the previous row's hash. Changing, removing or reordering any row breaks every hash after it, so tampering shows.
The chain cannot prove, on its own, that nothing was cut off the end, or that someone who owns the database did not rebuild it from scratch. For that, keep a copy of the newest link (the head: its number and hash, shown in the console) somewhere the database owner cannot reach, and compare it at your next check.
Use it
In the console, Audit (under Governance) lets administrators:
- search the trail by action, target, actor or person, and by date;
- check that the chain holds, and see its head;
- download it, as JSON lines for checking or as CSV for a spreadsheet.
Checking and exporting are themselves recorded in the trail.
Check an export yourself
You do not have to trust the platform's own check. Take the JSON-lines export of the whole chain and, for each row in order:
- Remove
hashandprevHashfrom the row. - Write what is left as JSON with keys sorted at every level and absent values left out.
- Compute SHA-256 of the previous row's hash, a newline, and that JSON. It must equal the row's
hash.
For the first row, the previous hash is SHA-256 of aioe-audit:v1: followed by your organisation's id. An export of a date range starts part-way along the chain: its first row's prevHash is your starting point, and every row after it must follow.
For administrators: Audit.