Audit log and activity review

Who changed what? Start with the record.

When a record raises a question, give your governance team a place to start. Review recorded activity, check the available user details and inspect changes before following the evidence further.

Illustrative audit entry

Care plan updated

Update
Timestamp
25 Sep 2026 · 10:42
User
Demo reviewer A
Resource
CarePlan · DEMO-001

Recorded change

Review date: 30 Sep 2026

Fictional details. Simplified from the audit-trail fields; change details vary by recorded event.

From a question to the supporting record

Find the entry. Follow the context.

The useful question is specific: which record, what action and whose involvement? Start there, then bring the activity entry together with the records needed to understand what happened.

01

Find the relevant activity

Search the loaded entries by user, action, resource or IP address. Narrow the view with action and resource filters. Choose columns and display density to make the review easier to scan.

Keep the search and filters in the page URL for returning to the same view.

02

Read the entry in context

Review the timestamp, recorded actor, action and resource reference. Inspect change details where supplied, then open the operational record separately to compare its context.

Use the entry as a starting point for the conversation with the responsible team.

03

Prepare the evidence you need

Use relevant activity entries alongside case notes, documents and external acknowledgements. Define the period and records required for your review before assembling an evidence pack.

Agree wider historical retrieval and export requirements during evaluation.

A practical review

A care-plan date has changed. What happens next?

Search the recent entries for the care-plan reference. Where the filter lists an update action, select it, then review the recorded user, timestamp and change details. Open the care plan separately to inspect the associated notes.

If the relevant event falls outside the loaded window, arrange the wider retrieval required for the review. Keep the scope of your evidence clear when handing it to a colleague or assembling a governance pack.

Bring a record-review scenario to the demo.

Check the events and evidence your team would need for a real investigation or governance review.

Find an entry
Search the loaded activity and filter by action and resource.
Inspect its context
Review available user details, the timestamp, resource reference and recorded changes.
Define the evidence scope
Confirm the history, event coverage and retrieval arrangements needed for your review.

Include retention, export and privileged-access requirements in your evaluation.

Audit-trail questions, answered.

What information does an audit entry show?

The audit view shows recorded timestamps, users, actions, resources and resource references, with change details and IP addresses where available. The fields available depend on the event that was recorded.

Does the page show the complete audit history?

The current audit-trail screen loads the latest 100 entries for the provider scope. Its search and filters operate on that loaded set. It is a recent activity view, not a complete historical search. Confirm the period, event coverage and retrieval process you need during evaluation.

Does an entry prove that every access or change was logged?

No. An entry is evidence of the event recorded. It does not by itself establish complete coverage of every page view, record access or change. Review the event coverage required for your specific clinical, workforce, finance or security workflow.

How long are records retained, and can we export them?

Confirm the retention, historical retrieval, export format and access arrangements required for your service before purchase. The recent audit-trail screen does not establish a contractual retention period or a universal export/API capability.

Can staff edit entries from the audit-trail screen?

The audit-trail screen presents entries for review and does not provide controls to edit or delete them. That screen behaviour is distinct from a wider assurance about storage integrity, privileged access or retention; include those requirements in your security review.