Skip to main content

How Do I Read the Audit Trail?

Every action in Zenoo Case Management is logged immutably. The audit trail provides a complete record of who did what, when, and why — essential for regulatory examinations, internal compliance reviews, and dispute resolution.

What you’ll learn

  • Where to find the audit trail
  • What events are logged
  • How to filter and search audit entries
  • How to export data for regulatory reporting
  • What the maker-checker audit pattern looks like

Where is the audit trail?

The audit trail is accessible in two places:
  1. On a specific case or alert — scroll to the Audit Trail section in the detail view to see all events for that record
  2. Global audit trail — available from the main navigation for compliance officers and administrators who need to search across all records

What events are logged?

The audit trail captures 32 event types across seven categories:

How do I filter audit entries?

The audit trail panel provides filters to narrow your search:
1

Filter by event type

Select one or more event types from the dropdown (e.g., show only “Case Escalation” and “Risk Tier Override” events).
2

Filter by date range

Set a start and end date to view events within a specific period. Useful for regulatory examinations that cover a defined timeframe.
3

Filter by actor

Search for events performed by a specific user. The audit trail stores both the user ID and their name at the time of the event — so even if a user is deactivated, their name is preserved.
4

Search by keyword

Use the search bar to find events containing specific text in their description, old value, new value, or reason fields.

What does an audit entry show?

Each audit entry contains:
Audit entries are immutable. Once created, they cannot be edited or deleted — not even by administrators. This is enforced by a validation rule at the database level.

How do I export for regulatory reporting?

Click the Export CSV button at the top of the audit trail panel. The export includes:
  • All visible entries (respecting your current filters)
  • All fields in a flat CSV format
  • Timestamps in ISO 8601 format for easy processing
  • UTF-8 encoding
The CSV can be provided directly to regulatory examiners or imported into your organization’s compliance reporting system.
Before a regulatory examination, use date range filters to export only the relevant period. Include all event types unless the examiner requests specific categories.

What is the maker-checker pattern?

The audit trail supports the four-eyes principle (maker-checker) used in regulated environments:
  • Maker — the analyst who performs an action (e.g., resolves an alert, overrides a risk tier)
  • Checker — the approver who validates the action (e.g., a senior reviewer who approves the case)
The audit trail links these events with approved-by and approved-date fields, providing a clear chain of accountability that satisfies regulatory requirements for dual authorization.

What’s next?

Resolve a Case

See how case lifecycle events appear in the audit trail.

Track SLA Compliance

SLA breaches and auto-escalations are logged for review.

Understand Risk Scores

Risk overrides are fully audited.

Collaborate With Your Team

Comments and reviewer actions appear in the audit trail.