Settings → Audit trail shows every recorded action in your organisation: case workflow, settings changes, provisioning, report generation, sign-ins to sensitive capabilities — each with actor, action, target and time.
The audit trail

Why it can be trusted

The log is append-only and hash-chained:
  • Entries are never edited or deleted — corrections are new entries.
  • Each entry stores a cryptographic hash of its content plus the hash of the previous entry. Editing, deleting or reordering any historical entry breaks every hash after it.
  • The platform team can re-walk the whole chain on demand to verify integrity end to end.
This is what makes the trail evidence rather than just a log: you can demonstrate, not merely assert, that the record hasn’t been altered.

Reading entries

Entries that touch a case link straight to it, and each shows the acting role at the time — including when a platform Global Admin acted within your organisation, which is itself always recorded.
The audit trail is visible to Org Admins and above. It records that things happened — never report content: like everything else in Secure Report, the reporter’s words stay in the intake system.