Audit trails in UniAsset
UniAsset keeps several distinct trails. They are not interchangeable — each answers a different question.
The trails
| Trail | Answers | Where |
|---|---|---|
| Asset events | What happened to this asset, and who did it? | The asset's timeline |
| Incident snapshot | What did this asset look like at the moment of the incident? | The incident |
| Escalation log | Which escalation levels fired on this work order? | The work order |
| Billing events | What happened to this subscription financially? | Settings → Billing |
| Integration event log | What did this API key do? | Settings → Integrations → Activity |
| User login log | Who signed in, from where? | Settings → Profile |
| DPA acceptance | Who accepted which agreement version, and from where? | Recorded immutably |
None of them can be edited
Every one of these is append-only. Records are written once and never modified or deleted — not by you, not by an Owner, not by support.
Correcting a mistake means writing a new record that supersedes the old one, never editing the original.
This is a product commitment rather than a technical limitation. The value of an operational record is proportional to how much it can be trusted, and trust requires that history cannot be quietly rewritten. When an audit happens, when an insurance claim is filed, when a post-incident review runs, the record reflects what happened — not what someone decided afterwards it should say.
The asset timeline
The one you will use most. Every asset carries its complete history: every change, assignment, document, service, scan, movement, geo-position update, check-out, check-in, signal, archival, and disposal — each with the acting user and a timestamp.
The incident snapshot
Stronger than a timeline entry. When an incident is reported, the asset's complete state — condition, assignment, maintenance history, document status — is captured into the incident and locked.
Later changes to the asset do not alter what the incident says the asset looked like. This is what makes an incident usable as evidence in an insurance claim, a regulatory submission, or a root cause analysis: the evidence is fixed at the time of the event rather than reconstructed afterwards.
The integration event log
(Odyssey and above, Owner only)
Every API request against your keys: endpoint, key, IP address, status code, timestamp, and a sanitised request body.
Failed and rejected requests are recorded as faithfully as successful ones — which is exactly what makes the log useful when an integration breaks.
Archive rather than delete
Assets, documents, images, people, locations, departments, categories, statuses, custom fields, PM rules, and checklist templates all archive. History stays attributable and the action is reversible.
Hard deletion is reserved for the deliberate erasure of an entire organization.
Using the trails for an audit
- Asset timeline for what happened to a specific asset.
- Service records for evidence that scheduled maintenance was carried out.
- Compliance report for document and certification status.
- Fixed Asset Register for the financial position, including disposed assets.
- Export anything you need as CSV, Excel, or PDF.
See Audit preparation.
Related articles
Need Help?
If you have questions not covered in this article, our support team is here to help.
Contact Support