Find who signed in, changed access or configuration, or acted on your organisation, read each sealed entry, and prove that nothing in the trail has been altered.
The Audit Trail is the tamper-evident record of who did what in your organisation: sign-ins and failed sign-ins, changes to users, roles and permissions, configuration changes, and every action ComplyTrain platform staff take on your organisation. Use it to answer an auditor's question about access or a change, and to show that the record has not been altered since it was written.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
Only organisation Admins can open Audit Trail and verify it. The page does not appear in the Settings navigation for other users. The trail covers your organisation only.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
Each entry records one action: when it happened, who performed it, what the action was, whether it succeeded, the IP address it came from and the details recorded for that action, such as which roles were granted to whom. Among the actions recorded are:
sign-ins, failed sign-ins and ended sessions;
users invited, created, enabled or disabled, and password resets;
roles, permissions and user groups changed;
organisation configuration changed, for example the company profile or residual-scoring settings in Risk Management;
archiving, restoring and deleting AI conversations;
decisions such as a Statement of Applicability being sent back or approved;
actions that ComplyTrain platform staff take on your organisation.
Every entry is sealed when it is written. The seal is a cryptographic fingerprint of the entry's content and of the entry before it, so the entries form a chain. Once protection is in place, entries cannot be changed or removed, and any later change, deletion or reordering is detected when the trail is verified.
The audit trail is not the list of individual requests made to ComplyTrain. For that operational view, see API activity. The page links to it under Looking for individual API requests?
Product location: /settings/audit-trail. Open Audit Trail in Settings.
Open Settings, then Audit Trail. The page shows Your tamper-evident audit trail, then the Integrity panel, the filters and the Entries list, newest first, 50 entries per page. The heading of the list shows how many entries match.
If the page shows Audit trail not yet protected, a pending system update switches on tamper-evident protection for your organisation. Entries are still recorded, but they are not sealed and cannot be verified until the update is applied.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
Filter | How it works |
|---|---|
User | All users, or one person who appears in the trail. |
Action | All actions, or one action identifier that appears in the trail, for example |
Outcome | All outcomes, Succeeded or Failed. Failed entries are attempts that were refused or failed, such as a failed sign-in. |
From, To | The first and last day of the period, in your own time zone. Both days are included in full. Leave a date empty for an open-ended range. |
Select Apply to show the first page of matching entries. If From is later than To, the page asks you to correct it: The start date must be on or before the end date. Clear removes every filter and shows the whole trail again.
No matching entries means that nothing matches the current filters. Adjust or clear the filters before you conclude that an action did not happen.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
Column | What it shows |
|---|---|
Time | When the action was recorded. |
User | Who performed the action, with their email address. System means an automatic process. Platform staff or removed user means the person has no user account in your organisation, typically ComplyTrain staff acting on your organisation. |
Action | The action identifier, for example |
Outcome | Succeeded or Failed. |
IP address | Where the request came from. |
Seal | The entry's position in the chain, for example |
Seal | Meaning |
|---|---|
Sealed | Sealed with the server-held key. Proves that the entry is unchanged and that ComplyTrain wrote it. |
Sealed (unkeyed) | Sealed with the older digest that uses no key. Proves that the entry is unchanged, but not who wrote it. |
Not sealed | Written before tamper-evident protection was switched on. The entry is kept, but it cannot be verified. |
Select Details on a row to see everything recorded with the entry: Entry ID, User ID, Session ID, Seal algorithm, User agent, Reason for failure for a failed action, and Recorded details, the action's own details. Select Hide to close them. Use the page controls under the list to move through the results.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
The Integrity panel checks the audit trail and every other tamper-evident log in your organisation, such as the QMS audit events, the document vault logs and the risk register log. The check runs only when you ask for it.
Select Verify now. ComplyTrain recomputes every sealed entry from its content and checks every link in each log. With a long history this can take a moment.
Read the overall result, and the row for each log.
To check again later, select Verify again. The result shows when it was verified.
Result | Meaning |
|---|---|
All audit logs intact | Every sealed entry matches its content and links to the one before it. Nothing in the sealed part of the logs has been altered, removed or reordered. |
Not every log is protected yet | Nothing written since protection was switched on failed verification, but at least one log is not protected yet or has earlier history that cannot be re-verified. The rows show which. |
Tampering detected | At least one log failed verification. Its row names the first failing entry, for example At entry #9041:, and the reason. |
If the result is Tampering detected, treat it as a security incident. Note the entry number and reason, find the entry in the list by its seal number, keep the evidence and contact ComplyTrain support.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
Each log has a row with its Status: Intact, Broken, Not yet protected or Legacy history does not link. Document vault logs are kept per vault, so they appear under Document vault logs with a row per vault. A vault that has been deleted keeps its log and is marked Vault deleted.
Column | What it counts |
|---|---|
Entries verified | Sealed entries that were checked. |
Unkeyed seal | Entries sealed without the server key: unchanged, but not provably written by ComplyTrain. |
Linkage only | Entries whose place in the chain could be checked, but not their content. |
Before protection | Entries written before protection was switched on. They carry no seal and cannot be verified, and they are not evidence of tampering. |
Finding | For a broken log, the first failing entry and the reason. |
Legacy history does not link is a warning, not a failure. History written before protection was switched on, for example entries carried over from an earlier version, does not link into the chain and can never be re-sealed. Everything written since protection was switched on was verified on its own and is intact.
Not yet protected means a pending system update has not been applied to that log. Its entries are recorded but cannot be verified. Once the update is applied, every new entry is sealed.
Product location: /settings/audit-trail. Open Audit Trail in Settings.
An auditor asks who gave a colleague a new role in March 2026.
Open Audit Trail.
Under Action, choose user_roles_updated.
Under From and To, enter 1 March 2026 and 31 March 2026, and select Apply.
Find the entry and read User for who made the change and Time for when.
Select Details. Recorded details shows whose roles changed, with the previous and the new roles.
Select Verify now and keep the result with your answer to show that the trail is intact.
To see the person's current roles, open them in users, roles and groups.