IT Glossary
An audit trail is a chronological record of who did what, when. Learn how audit trails work, what they record in IAM, and why compliance needs them.
July 3, 2026
An audit trail is a chronological, tamper-evident record of activities, events, and changes within a system, showing who did what, when, and to which resource. In identity and access management, audit trails document access grants, modifications, reviews, and removals, providing the evidence auditors require for ISO 27001, SOC 2, and NIS2 compliance.
An IAM audit trail records each access event with its detail. When access is granted, it captures who, to what, when, and by whom. When access changes, it captures the old and new permissions. When access is reviewed, it captures the reviewer, decision, and date. When access is removed, it captures the trigger and timestamp.
During a SOC 2 audit, an assessor asks for evidence that a specific employee's access was granted, reviewed, and later revoked. A complete audit trail produces it in seconds. Without one, the company cannot prove its controls worked, even if they did. Across many SaaS apps, audit trails are scattered and inconsistent, so a unified, exportable record of access events across the stack is what makes audits manageable.
Access events: who was granted, changed, reviewed, or removed from access, when, and by whom, each with a timestamp for accountability.
Because they provide the evidence that controls operated as intended. Auditors for ISO 27001, SOC 2, and NIS2 sample audit trails as proof.
Each app keeps its own logs in its own format. A unified, exportable trail across the stack is what makes cross-app audits practical.