Archive · Chain of Custody · Audit Log
Verified by an auditor who cannot read a single document
Container hashes recomputed, a hash-chained ledger walked link by link, a root hash for anchoring outside the system — and an auditor role with read access to the record of what happened, and none to the material itself.
Where it starts
Someone has to be able to check — a regulator, an external auditor, opposing counsel's expert. The auditor role exists for exactly that person: read the ledger and the compliance state, and nothing else. Read access to the record of what happened is a different thing from read access to the material.
How it runs
- 01
Press Verify
Container hashes are recomputed and the ledger chain walked. Verification samples by default — least-recently-verified containers first, so coverage accumulates — because a verification nobody can afford to run is a control that exists on paper. A full pass is one flag away for the annual attestation.
- 02
Read a claim, not a checkmark
The result states exactly what it entitles you to conclude: only a full pass says the archive is intact; a clean sample says something weaker, and the word on screen reflects which — the same figure cannot mean two different things on two days.
- 03
Anchor the root outside the system
The screen shows the root hash and tells you the uncomfortable truth: without an external copy, somebody who controls the archive could rewrite an entry and re-chain everything after it, and verification would still pass. Publish the root; write it down somewhere else.
- 04
Filter the log like an investigator
By action, by person, by date, by matter, by document — and export to CSV, with every field neutralised against formula injection, because a ledger detail carries archived values and an archived value is whatever somebody sent. The export itself becomes a ledger entry.
- 05
Know what to look for
The help panel briefs the auditor: destructions should carry two distinct names — one who asked, a different one who approved. Exemptions are the proof holds worked. And refusals: an archive with none in its log is one where nothing was ever attempted that should not have been — rarer than it sounds.
Why it holds up
What you hand the regulator
A workflow that ends on a screen isn’t finished. This one ends in a document.
The integrity result with its claim stated in words, the audit-log export, and a root hash you can anchor outside the system — the package an external auditor takes away.
- containers verified · records sealed · ledger entries · chain INTACT
- the claim: what this verification does and does not establish
- root hash + head hash for external anchoring
- audit-log.csv: timestamp · action · actor · doc count · matter · entry hash
Adjacent workflows
See it run on your data scenario
The demo form asks which workflows you want to see — name this one and we’ll stage it.