Skip to content
Glossary

What is an audit log?

When something goes wrong, or an auditor asks, the audit log is how you answer "who did this?" with evidence.

Plutonapps Engineering1 min read

In short

An audit log is a permanent, append-only record of significant actions in a system: who did what, to which record, when and from where. Unlike application logs, which help engineers debug, an audit log is evidence. It must not be editable by the people it records, and it is what security reviews, SOC 2 auditors and investigations rely on.

Also called: Audit trail, Activity log

Why it matters when your prototype goes to production

A prototype rarely records anything beyond errors. Then a customer asks who deleted their project, a team member's access has to be investigated, or a security questionnaire asks how you trace administrative actions. Without an audit log, the honest answer is that nobody knows.

What to record

  • Sign-ins, failed sign-ins and changes to roles and permissions.
  • Anything staff do inside customer accounts.
  • Exports, deletions and changes to billing.
  • Actions taken by AI agents or integrations, attributed to the person who allowed them.

In practice: Inkwave writes every operator action to an append-only audit log. Bell records who authorised every send, reply and calendar invite, and its database refuses one no person approved.

Common questions

Should audit logs be immutable?

Yes, in practice: append-only, with no way for the people being recorded to edit or delete entries, and kept for as long as your obligations require.

What is the difference between an audit log and an audit trail?

They are usually the same thing. Audit trail sometimes means the full chain of records around one transaction.

More on this: Production architecture & security · All glossary terms

Built something in Lovable you want people to rely on?

We are the engineers who take it the rest of the way — secured, tested, released and supported.