Skip to main content

Audit Trail Overview

A list of all records posted to the Audit Trail Report

S
Written by Susan Griffith

Compliance & Integrity Statement

Qualio's audit trail is computer-generated, secure, timestamped, and aligned with GAMP 5, ALCOA+ principles, 21 CFR Part 11 §11.10(e) and §11.300(c)–(d), and EU Annex 11 §12. Every entry is attributable to an individual user via unique credentials. Audit trail entries are immutable - they cannot be modified or deleted, including by administrators, and there is no UI functionality to alter them.

The audit trail generates a list of auditable actions along with:

  • The user that performed the action

  • The type of action

  • The related target (record)

  • The date and time of the action

  • The IP address and geo-location of the user that performed the action.

    • Note: The geo-location of the user who performed the action is approximate, and city-level accuracy will vary depending on several factors outside Qualio’s control.

To view your audit trail, click on the Reports tab and then select Audit trail.

Note: Access to the audit trail for documents requires the Quality User role, which is designed to ensure that only personnel with appropriate permissions can review sensitive activity logs. This role-based restriction supports segregation of duties per GAMP 5 and 21 CFR Part 11.


Retention

Audit trail records are retained within Qualio indefinitely for the lifetime of the customer's system. There is no mechanism for premature deletion of audit trail records, ensuring records remain available for regulatory inspection for at least as long as the associated electronic records - per 21 CFR Part 11 and EU Annex 11.

Data backup and security are managed under Qualio's POL-14 Data Security, Backup & Redundancy.

Audit Trail vs. Document Activity Log

Qualio uses two complementary records to support GAMP 5 data integrity expectations:

  • Audit Trail: captures system-level actions (who, what, when, where) across the platform.

  • Document Activity Log: captures document-level before/after value changes, displayed alongside the document's full version history. Superseded versions of documents are retained, and changes between versions are traceable through the activity log and document change history.

  • Document Activity Log records the previous and new values for field-level changes (e.g., document owner, review date, title) and is accessible from the Activity tab on the document record itself. It complements the audit trail's system-level entries by providing the granular before/after data that GAMP 5 §4.3 and ALCOA+ "attributable and original" principles require for individual record changes.

This separation ensures clarity: the audit trail provides system-wide traceability, while the activity log provides document-specific before/after value capture aligned with GAMP 5's data-integrity expectations.

Security Events in the Audit Trail

The following security-related events are automatically captured in the audit trail:

  • Password changes (per 21 CFR Part 11 §11.300(c))

  • Failed login attempts and progressive lockout (per §11.300(d))

  • Successful logins

  • SSO / SAML configuration changes

  • User account creation, deletion, and permission changes

  • Group membership changes


View Audit Trail entries for:


Documents

Note: The audit trail captures action-level events for documents (listed below). Field-level before/after value changes are recorded separately in the document's Activity Log. See Audit Trail vs. Document Activity Log above.

  • Draft Created

  • Approved (comments included)

  • Template Restored

  • Draft Deleted

  • Approval Declined (comments included)

  • Periodic Review Sent for Approval

  • Reverted to Draft

  • Made Effective (automatically, marked as "System" or manually by user)

  • Periodic Review Approved

  • Sent for Review

  • Change Control Approved

  • Change Control Template Updated

  • Reviewed (document was reviewed)

  • Template Created

  • Periodic Review Completed

  • Review Date Changed

  • Template Updated

  • Retired (effective documents only, comments included)

  • Sent for Approval

  • Template Archived

  • Document Owner Changed

  • Added Tag to Document

  • Removed Tag from Document

  • Approver(s) modified (For Review and For Approval statuses only)

  • Controlled Export Created

  • Periodic Review Approval Declined


Tags

  • Created Tag

  • Deleted Tag

  • Group Added to a tag

  • Group Removed from a tag

  • Modified Tag


Training

  • Added Trainee

  • Training completed (on a Document, by assigned user)

  • Removed Trainee

  • Training Setting Modified (in Org Settings)

  • Create Training Plan

  • Update Training Plan

  • Retire Training Plan


Events

  • Created Event

  • Signed off on Actions

  • Resolved Event

  • Created Task

  • Approval Declined

  • Re-opened Actions

  • Step Created

  • Closed Event

  • Owner Changed

  • Sent for Approval

  • Closed Task as Failed

  • Event Template Changed

  • Event Actions Signed Off

  • Closed Task as Success

  • Event Step Status Changed

  • Event template Draft Created

  • Event Template Archived

  • Event Template Unarchived/Restored

  • Event Root Cause Created

  • Event Root Cause Updated

  • Event Step Reverted

  • Event Product
    Created

  • Event Product Updated

  • Event Root Cause

  • Task Comment Added

  • Updated Task

  • Event Product

    Deleted

  • Adding/Removing Tags

  • Event Template

    Made Effective

  • Event Template Draft

    Deleted

  • Created Event Form Draft

  • Cancelled Event Form

  • Reassigned Event Form

  • Reviewed Event Form

  • Approved Event Form

  • Rejected Event Form

  • Event Form Sent for Review

  • Event Form Sent for Approval


User Management

  • User Added (i.e. invited)

  • User Time Zone Change

  • Password Expiry Changed

  • User Accepted Invitation

  • Documents, Events, Tasks or other items reassigned due to user removal from company

  • Company Logo Change

  • User Declined Invitation

  • Modified user account (e.g. user name changed)

  • Grant/Remove Billing Permission

  • Cancel Invitation Sent

  • Create, Edit or Delete Groups

  • Log in Lock Out (Failure)

  • Manager of Group Assigned

  • Manager of Group Removed

  • User Added/Removed from a group

  • User Removed from Company

  • User Account Deleted

  • Sign in failed (e.g. wrong password/e-mail)

  • Password Changed

  • Changes to SSO/SAML configurations

1: Modified user account entries include granting Admin or Billing Access and Event permissions.


Suppliers

  • Supplier Created

  • Supplier Updated

  • Supplier Sent for Approval

  • Supplier Reverted to Draft

  • Supplier Reverted to Draft from Archived

  • Supplier Review Updated

  • Supplier Approved

  • Supplier Rejected

  • Supplier Archived

  • Supplier Approval Accepted

  • Supplier Approval Declined

  • Created Policy

    Configuration

  • Modified a Policy Configuration

  • Created a Supplier Policy

  • Modified a Supplier Policy

  • Created a Supplier Audit

  • Deleted a Supplier Audit


Design Controls

Design Controls: Configuration

  • Created Product

  • Created Test Case Level 2 Policy

  • Deleted Test Case Level 3 Policy

  • Modified Product

  • Created Test Case Level 3 Policy

  • Modified Risk Policy

  • Deleted Product

  • Deleted Risk Policy

  • Modified Requirement Level 1 Policy

  • Created Risk Policy

  • Deleted Requirement Level 1 Policy

  • Modified Requirement Level 2 Policy

  • Created Requirement Level 1 Policy

  • Deleted Requirement Level 2 Policy

  • Modified Requirement Level 3 Policy

  • Created Requirement Level 2 Policy

  • Deleted Requirement Level 3 Policy

  • Modified Test Case Policy

  • Created Requirement Level 3 Policy

  • Deleted Test Case Policy

  • Modified Test Log Policy

  • Created Test Case Policy

  • Deleted Test Log Policy

  • Modified Document Policy

  • Created Test Log Policy

  • Deleted Document Policy

  • Modified Test Case Level 1 Policy

  • Created Document Policy

  • Deleted Test Case Level 1 Policy

  • Modified Test Case Level 2 Policy

  • Created Test Case Level 1 Policy

  • Deleted Test Case Level 2 Policy

  • Modified Test Case Level 3 Policy


3rd Party Integration with Design Controls

  • Created Requirement Level 1 Integration

  • Modified Requirement Level 1 Integration

  • Deleted Requirement Level 1 Integration

  • Created Requirement Level 2 Integration

  • Modified Requirement Level 2 Integration

  • Deleted Requirement Level 2 Integration

  • Created Requirement Level 3 Integration

  • Modified Requirement Level 3 Integration

  • Deleted Requirement Level 3 Integration

  • Created Test Case Integration

  • Modified Test Case Integration

  • Deleted Test Case Integration

  • Created Test Case Level 1 Integration

  • Modified Test Case Level 1 Integration

  • Deleted Test Case Level 1 Integration

  • Created Test Case Level 2 Integration

  • Modified Test Case Level 2 Integration

  • Deleted Test Case Level 2 Integration

  • Created Test Case Level 3 Integration

  • Modified Test Case Level 3 Integration

  • Deleted Test Case Level 3 Integration

  • Created Risk Integration

  • Modified Risk Integration

  • Deleted Risk Integration

  • Created Test Result Integration

  • Modified Test Result Integration

  • Deleted Test Result Integration

  • Created Document Integration

  • Modified Document Integration

  • Deleted Document Integration

  • Created Test Log Integration

  • Modified Test Log Integration

  • Deleted Test Log Integration


Design Elements: Requirements, Risks, and Test Cases

  • Created Risk

  • Modified Test Case

  • Deleted Document

  • Modified Risk

  • Modified Test Case Level 1

  • Created Requirement Level 1

  • Deleted Risk

  • Modified Test Case Level 2

  • Modified Requirement Level 1

  • Created Test Log

  • Modified Test Case Level 3

  • Deleted Requirement Level 1

  • Modified Test Log

  • Deleted Test Case

  • Created Requirement Level 2

  • Deleted Test Log

  • Deleted Test Case Level 1

  • Modified Requirement Level 2

  • Created Test Case

  • Deleted Test Case Level 2

  • Deleted Requirement Level 2

  • Created Test Case Level 1

  • Deleted Test Case Level 3

  • Created Requirement Level 3

  • Created Test Case Level 2

  • Created Document

  • Modified Requirement Level 3

  • Created Test Case Level 3

  • Modified Document

  • Deleted Requirement Level 3

Design Controls: Change Control

  • Created Change Control

  • Not Approved Change Control

  • Modified Change Control

  • User Not Approved Change Control

  • Approved Change Control


Integrations

  • Add Connection Configuration

  • Update Connection Configuration

  • Delete Connection Configuration

  • Enable Integration

  • Disable Integration

  • Update Integration Configuration


Compliance Intelligence

  • Created Framework

  • Modified Framework

  • Framework Status Changed

  • Deleted Framework

  • Started Gap Assessment

  • Created Control

  • Modified Control

  • Control Status Changed

  • Deleted Control

  • Changed Control Owner

  • Updated Control Definitions

  • Updated Control Evidence

  • Updated Control Monitor

  • Created Requirement

  • Deleted Requirement

  • Modified Requirement

  • Requirement Status Changed

  • Mapped Control To Requirement

  • Created Task

  • Completed Task

  • Canceled Task

  • Modified Task

  • Reopened Task

  • Task Comment Added

  • Changed Task Assignee

  • Created Gap

  • Resolved Gap

  • Dismissed Gap


Periodic Review of Audit Trails

GAMP 5 requires periodic review of audit trails as part of ongoing system lifecycle management. Qualio provides the search and export functionality to enable this.

Customers are responsible for establishing their own SOP defining the cadence, scope, and reviewer roles for periodic audit trail review within their own quality management system.

Shared Responsibility (Cloud / SaaS Model - GAMP 5 2nd Edition)

As a cloud-hosted SaaS platform, Qualio operates a shared-responsibility model:

  • Qualio is responsible for the integrity, security, availability, and immutability of the audit trail at the platform level.

  • Customers are responsible for defining their internal procedures for audit trail review, training, and the use of audit trail data as evidence within their QMS.

Supplier responsibilities are detailed in the Qualio MSA, DPA, and supporting validation documentation.


For Additional information on the Audit Trail see:

  • Understanding permission roles in Qualio

  • Best practices for audit trail review

  • For validated-system evidence supporting GAMP 5 compliance (IQ/OQ/PQ, validation summary, traceability matrix), contact your Qualio account team to request VAL-17 Qualio System Validation document under NDA.

For further details, consult the Qualio Help Center or contact support for additional guidance.

Did this answer your question?