UniAsset
Home/Knowledge Base/Core Concepts/Immutable Incident Snapshots — Why the Evidence Cannot Change
Back to Core Concepts

Immutable Incident Snapshots — Why the Evidence Cannot Change

4 minIntermediateLast updated: January 2, 2026

Immutable incident snapshots

When an incident is reported against an asset, UniAsset captures the asset's complete state at that moment and locks it. This article explains what that means and why it matters.

The problem it solves

A forklift fails on Tuesday and injures nobody, but does £40,000 of damage. On Wednesday someone fixes it, updates its status, uploads a new inspection certificate and changes its assigned person.

Three months later the insurer asks: what condition was that forklift in on Tuesday, and when was it last serviced?

If your system only holds current state, you cannot answer honestly. The record has moved on. You are left reconstructing Tuesday from memory — which is exactly the kind of evidence that does not survive scrutiny.

What a snapshot captures

At the moment an incident is created, UniAsset writes the asset's complete state into the incident:

  • Condition and status at that time
  • Assignment — who was responsible, where it lived, which department owned it
  • Maintenance history as it stood
  • Document status, including which certificates were current and which had lapsed

That snapshot is locked. It cannot be edited afterwards, by anyone, including the Owner.

What locked actually means

Later changes to the asset do not alter what the incident says the asset looked like. The two records diverge from the moment the incident is created, and that divergence is the whole point.

You can still:

  • Add threaded notes to the incident as the investigation progresses
  • Move the incident through its statuses — Open, Investigating, Resolved, Closed
  • Continue changing the asset itself, normally

You cannot:

  • Edit the snapshot
  • Backdate it
  • Recreate it as it "should have been"

Requirements

  • Available on: Orbit, Odyssey, Cosmos — incidents are part of the maintenance capability
  • Roles: Owner, Admin, Manager, Employee can report an incident

Where snapshots fit among UniAsset's records

Snapshots are one of several append-only trails. They are not interchangeable.

TrailAnswers
Asset eventsWhat happened to this asset, and who did it?
Incident snapshotWhat did this asset look like at the moment of the incident?
Escalation logWhich escalation levels fired on this work order?
Stock ledgerHow did this quantity reach its current balance?
Login logWho signed in, from where?
Billing eventsWhat happened to this subscription financially?

Every one of them is written once and never modified. Correcting a mistake means writing a new record that supersedes the old one, not editing history.

Why UniAsset works this way

The value of an operational record is proportional to how much it can be trusted, and trust requires that history cannot be quietly rewritten.

This is a product commitment rather than an implementation detail. When an audit happens, when an insurance claim is filed, when a post-incident review runs, the record reflects what happened — not what someone decided afterwards that it should say.

Practical uses

Insurance claims. The snapshot proves the asset's condition and service position at the time of loss, without you having to assemble it retrospectively.

Regulatory submissions. Where a regulator requires evidence of the state of equipment at the time of an event, the snapshot is that evidence.

Root cause analysis. Investigators can see whether a certificate had lapsed, whether maintenance was overdue, and who was responsible — as it was, not as it is now.

Internal reviews. A post-incident review that argues over what the record said is not a review. The snapshot removes that argument.

Common mistakes

Reporting the incident late. The snapshot captures state at the moment of reporting, not the moment of the event. Report incidents promptly — a snapshot taken after the repair is a snapshot of the repaired asset.

Fixing the asset before reporting. Same problem. If you update the status, attach the new certificate and reassign the asset first, all of that is what the snapshot records.

Expecting the snapshot to include future notes. Notes you add later live on the incident as a threaded discussion. The snapshot itself stays as it was.

Troubleshooting

I need to correct something in a snapshot. You cannot, and that is deliberate. Add a note to the incident explaining the correction. The note is part of the incident record and is visible alongside the snapshot.

Incidents are locked in my sidebar. Incidents require Orbit or above.

The snapshot looks wrong. It reflects the asset exactly as it was when the incident was created. If the asset's data was incomplete then, the snapshot honestly records that it was incomplete.

Related articles

Need Help?

If you have questions not covered in this article, our support team is here to help.

Contact Support