Commercial & Planning
Audit Logs
Every upload, edit, approval, deletion and access event, recorded and unalterable.
Overview
Immutable record of every action
Audit Logs maintain an immutable record of what happened on the platform: uploads, edits, approvals, deletions and access events, each with the user and timestamp attached.
It serves two purposes at once. On one side, ISO 27001 and internal compliance evidence produced as a by-product of normal use rather than as a separate exercise before an audit. On the other, evidence when a contractual position depends on proving who knew what, and when.
The word that matters is immutable. A log that an administrator can edit is not evidence, it is a convenience. Logs here cannot be altered after the fact by anyone, including the account holder, which is precisely what makes them worth having when a position is challenged.
- Immutable
- Every action captured
- ISO 27001 support
- Dispute evidence

How it works
What is recorded
Every document event
Upload, revision, download, deletion — with the user and timestamp.
Every approval
Who approved what, at which step of the chain, and what they changed first.
Every access event
Who opened a document, and when. Often the decisive question in a dispute.
Unalterable by design
No user, administrator or account owner can edit or remove a log entry.
Why it matters
On a live project
Compliance is automatic
ISO 27001 evidence is produced by using the system, not by a separate exercise before the audit.
Disputes have a factual basis
Who accessed a document, and when, becomes a matter of record rather than recollection.
Unalterable by design
Logs cannot be edited after the fact, including by administrators, which is what makes them worth having.
Use cases
Where it is used
ISO 27001 audit
Access control and retention evidence available on request rather than assembled beforehand.
Dispute and adjudication
Establishing knowledge and timing as a matter of record.
Internal governance
Confirming that delegation of authority was actually followed.
Questions
Frequently asked about Audit Logs
No. Logs are immutable for all roles, which is the property that makes them useful as evidence.
Retention is set to your requirement, and typically runs for the life of the project plus the limitation period applicable to the contract.
Yes, filtered by date, user, document or event type, in a format suitable for submission.
The logging controls are designed to align with ISO 27001. Certification of your own organisation remains your process; we provide the documentation to support it.
Automated Document Control
More in this part of the platform
See Audit Logs on your project
Take the next step and empower your projects with Fortis Sync.