VaultAP Docs

Audit Trail

VaultAP maintains an immutable audit trail that records every significant action taken within your organization. The audit trail is designed to satisfy compliance requirements and provide forensic evidence in the event of a security investigation.

Immutability

Audit trail entries are append-only. Once written, they cannot be modified or deleted — not by users, not by Admins, and not by VaultAP staff. Entries are retained for the full duration of your organization's configured data retention period.

There is no mechanism to edit or remove individual audit trail entries. This is by design. If you believe an entry was created in error, add a note to the relevant record explaining the situation rather than attempting to alter the trail.

Hash-Chain Integrity

Each audit trail entry includes a cryptographic hash of the previous entry, forming an unbroken chain. This mechanism, similar to a blockchain, ensures that any insertion, deletion, or modification of an entry would break the chain and be immediately detectable.

The hash chain works as follows:

  1. Each entry is assigned a sequential ID and a timestamp.
  2. The entry's content (action, user, target, metadata) is combined with the hash of the previous entry.
  3. A SHA-256 hash is computed over the combined data.
  4. This hash is stored alongside the entry and used as input for the next entry.

VaultAP automatically verifies the hash chain integrity on a regular schedule. If a break in the chain is detected, Admins are notified immediately via email and in-app notification.

What Is Logged

Every action that changes state or accesses sensitive data is recorded:

User Authentication

  • Login (success and failure)
  • Logout
  • MFA enrollment and verification
  • Password changes and resets

Invoice Actions

  • Invoice received (via email or manual upload)
  • Risk score assigned
  • Invoice approved
  • Invoice rejected
  • Invoice escalated
  • AI explanation generated

Vendor Actions

  • Vendor created (first invoice from new vendor)
  • Vendor bank details changed
  • Vendor information edited

Settings Changes

  • Organization settings modified
  • Risk configuration updated (with before/after values)
  • Notification settings changed

User Management

  • User invited
  • User role changed (with before/after role)
  • User deactivated
  • User reactivated

Each entry includes:

FieldDescription
TimestampWhen the action occurred (UTC)
UserWho performed the action (email and user ID)
ActionWhat was done (structured action type)
TargetThe entity affected (invoice ID, vendor ID, user ID, etc.)
MetadataAdditional context (e.g., old and new values for settings changes)
HashSHA-256 hash linking to the previous entry

Viewing the Audit Trail

Navigate to Audit Trail in the main navigation to view entries. The trail supports filtering by:

  • Date range
  • User
  • Action type
  • Target entity
View audit trailAdmin ✗Reviewer ✗Viewer ✗

CSV Export

Admins can export the audit trail as a CSV file for external analysis, compliance reviews, or archival.

Set filters

Apply any desired filters (date range, user, action type) to narrow the export.

Click Export CSV

Click the Export CSV button. VaultAP generates the file in the background.

Download

A download link is sent to your email when the export is ready.

Export audit trail as CSVAdmin ✗Reviewer ✗Viewer ✗

Tamper Detection

If the hash chain is broken — indicating that an entry has been inserted, modified, or removed — VaultAP triggers a tamper alert:

  • All Admins receive an immediate email and in-app notification.
  • The affected entries are flagged in the audit trail UI with a warning indicator.
  • The tamper event itself is recorded as a new audit trail entry.

A tamper alert is a critical security event. If you receive one, investigate immediately and contact VaultAP support at security@vaultap.com.