Skip to content

Audit and evidence

The audit trail is a list of what people and systems did that matters for safety. It is append-only: entries are added at the end and never changed or removed. Each company has its own trail.

Each entry carries a fingerprint that depends on the entry before it. This is the hash chain. If anyone changes, removes or slips in an entry afterwards, the chain no longer adds up, and checking it shows where.

  • Adding, removing, importing and exporting do-not-call numbers.
  • Adding and withdrawing consent, and consent captured on a call.
  • Creating and changing a calling rule.
  • Logging and updating a complaint.
  • Exporting the audit trail.
  • Playing or downloading a recording.
  • Downloading an evidence pack.
  • Listening in on, whispering to, hanging up or taking over a live call.
  • Starting, pausing and stopping a campaign.
  • Sign-ins, and what a platform operator does in your company.

To check the trail:

  1. Open Safety, then Audit.
  2. Under Check the records, select Check the audit trail.
  3. Read the result. “Records intact” gives the number of entries checked. “Problem found at entry N” names the first entry that does not match.

To read it:

  1. Under What happened, filter by What was done and About.
  2. Each row shows when, what, who, and the entry number. Select Show older entries for more.

To export it:

  1. Choose a period under Export covers: today, 7, 30 or 90 days.
  2. Select Export as CSV. The file lists the oldest entry first, up to 200,000 rows. The export is itself written to the trail.

Owner, admin and compliance can read, check and export the trail.

An evidence pack is a ZIP file about one person’s journey, for a dispute or a regulator’s question.

  1. Open the person’s journey record. See journeys.
  2. Select Download evidence pack.

It contains:

  • journey.json: the journey record.
  • consents.json: the permission records, with quotes.
  • transcripts.json: what was said.
  • qa_reviews.json: the quality reviews.
  • compliance_checks.json: every safety check for that person.
  • recordings/: the call recordings.
  • manifest.json: the size and fingerprint (sha256) of every other file, plus a missing list with a reason for anything that could not be included.

The download is written to the audit trail first. If it cannot be written, the pack is refused. The response carries an x-evidence-sha256 header with the fingerprint of the whole ZIP, so you can show it was not altered. A recording that fails its stored fingerprint is left out and listed as missing.

Owner, admin and compliance can download packs.