Current state answers “what is true now”. An audit trail answers “what happened, when, and who did it”—the only question that matters during an investigation, a dispute, or an access review.
What an audit trail is for
| Situation | Question it must answer |
|---|---|
| Access review | Who has had administrative rights, and since when? |
| Departure | What did this person access in their final weeks? |
| Customer dispute | What was recorded, and when was it changed? |
| Suspected data exfiltration | Who exported what, and how much? |
| Procurement questionnaire | What operational events are recorded at all? |
An investigation, step by step
Rehearse it before you need it
Run a tabletop exercise: assume a departing employee exported the customer list on their last day. Can you tell? How quickly? What would you tell affected customers, and who decides? Teams that have run this once respond in hours; teams that have not respond in weeks, badly.
The exercise usually surfaces the same three gaps: nobody owns the decision to notify, the logs are not queryable by a non-engineer, and the retention window is shorter than the time it takes to notice.
Retention is a real decision
Logs kept too briefly cannot support an investigation, since intrusions are often discovered long after they occur. Logs kept indefinitely become their own liability and their own storage bill. Pick a period deliberately, write down why, and align it with your legal obligations rather than with the default setting.
Who reviews, and how often
- Quarterly: administrative access list, multi-organization assignments, active API keys
- On every departure: revocation confirmed, records reassigned, evidence retained
- On incident: full trail query, scoped to the accounts and period in question
- Annually: whether what you record is still sufficient for what you now have to answer
What Vertex CRM provides
Vertex CRM includes administrative surfaces for reviewing configuration and certain operational events, alongside activity history on records. The product supplies visibility; your policy defines retention, review cadence, and who is authorised to look. Tools support policy—they do not replace legal advice on what you must retain or report.
Related: CRM data security, DPDP obligations, and activity logging.
Frequently asked questions
- Do audit logs replace legal advice?
- No—they support policy; counsel defines retention and obligations.
- Who reviews audit data?
- Security, compliance, and operations leaders during incidents or periodic access reviews.