What is Audit Trail?

An audit trail is a timestamped record of actions and changes made to a survey, its translations and the responses. It shows who did what and when so organisations can verify decisions, resolve disputes and meet regulatory requirements.

An audit trail (sometimes called an activity log or change log) captures a chronological record of events related to a survey: creation, edits to questions or translations, publication, responses, export/download actions and administrative actions (for example granting access or resolving a flagged translation). Each entry normally includes what changed, who performed the action, and when it happened. In regulated or public-facing processes an audit trail provides transparency and a verifiable history that supports accountability and compliance.

Usage example

A council publishes a consultation in multiple languages. Later, a resident asks why a question wording changed mid-consultation. The audit trail shows the original wording, the timestamped edit, which admin made the change, and whether translated wording was updated — helping the team explain the change and confirm which version participants saw.

Practical application

Audit trails matter because they: - Demonstrate compliance: provide evidence for data-protection, freedom of information or procurement audits. - Protect integrity: show that survey content, translations and responses haven’t been tampered with. - Support accountability: identify who made edits or accessed sensitive data. - Enable dispute resolution: recreate past states to answer questions about what participants saw or how responses were handled. - Improve quality control: track translation edits and participant flags to feed the translation improvement workflow. For Hearo users, an audit trail makes it possible to run inclusive, defensible consultations and to confidently manage translated content and responses over time.

FAQ

Who can view the audit trail?

Typically admins and designated reviewers can view the audit trail; participants don’t see the full log. Access is controlled by role-based permissions so only authorised staff can review sensitive entries.

Does the audit trail include personal data from responses?

Audit trails record actions (for example: 'response exported by user X at time T'), and may reference response IDs. They do not need to store full personal data within the log, but logs can contain identifiers that link to responses. Organisations should apply data-minimisation and retention policies consistent with privacy laws when storing audit records.

How long are audit trail records kept?

Retention periods vary by organisation and regulation. Many teams keep logs long enough to satisfy legal or policy requirements (for example during a consultation and for a set archive period afterwards). Hearo supports configurable retention and export so logs can be preserved or deleted according to your compliance needs.

Are audit trails tamper-proof?

An effective audit trail is designed to be append-only and to protect against silent edits. Technical measures include write-once storage, restricted permissions, exportable logs and cryptographic integrity checks. Exact guarantees depend on platform configuration and organisational controls, so verify the specific protections your provider offers.

Related blog posts