Legal asked for the record behind a $40,000 emergency freight approval from six months back. The team had a run history and a change log. Neither one said who approved it, what data they saw, or why.
Definition
The decision, the approver, the data they saw, and the timestamp are logged permanently. Six months later, someone can reconstruct why the $40,000 expedite was authorised.
Audit gets confused with "we have logs" more than any other layer. Run histories and change logs record that something happened. They rarely record who decided, what information was in front of them at the time, or why the threshold was met. A real audit trail answers a regulator's or opposing counsel's question in minutes, not after a week of reconstructing Slack history.
"We have logs." Why doesn't that count as an audit trail?
A system log records that an event occurred: a change, a run, a status update. An audit trail records the decision itself: who approved it, the data they were looking at, the threshold it was measured against, and the exact timestamp. Most operations have the first and call it the second. That's fine until a regulator, an auditor, or opposing counsel asks a specific question and the honest answer is "we'd have to reconstruct that."