Recruiting Basics

Audit Trail

An audit trail is the chronological record of actions taken inside a system: who did what, to which record, and when. In a hiring context it captures stage changes, field edits, permission grants, exports and deletions. Entries are written automatically and are normally read-only, so users cannot rewrite the history of their own actions.

What does a hiring system audit trail record?

Typically the actor, the action, the object and the timestamp, and often the source address or device. In recruiting that means stage moves and rejections, edits to candidate fields, notes added or removed, scorecards submitted and changed, offers created and approved, permission and role changes, bulk operations, record merges and deletions, and exports of candidate data. Better systems distinguish between a user action and one performed by an automation or an integration acting on somebody's behalf, which matters when you are trying to understand why a candidate moved stage at two in the morning. What is captured varies by product, so treat the list as a question to ask rather than an assumption. Raise export and delete events specifically when comparing [ATS features](/ats-features), because those matter most when something goes wrong and some systems log them least thoroughly.

Why does an audit trail matter when a hiring decision is challenged?

Because memory is contested and logs are not. When a rejected applicant questions how a decision was reached, or an internal complaint alleges a candidate was moved for the wrong reasons, the useful evidence is a dated sequence showing who did what. A trail can establish that a scorecard was submitted before the debrief rather than written afterwards to justify an outcome, that a candidate was rejected at the stage the team says, or that a field was edited after a decision was taken. It protects people too, since a recruiter accused of an action they did not take has a record showing which account performed it. All of this works only if the log is genuinely append-only and retained long enough to still exist when the question arises, which is frequently much later than the hiring itself.

How do audit trails support compliance and internal control?

They are the evidence layer underneath most controls. Access reviews rely on a record of permission grants. Data protection requests are easier to answer when you can show when a record was accessed, exported or deleted. Segregation of duties, such as requiring approval from someone other than the requester, is only enforceable if the log shows who approved what. Security investigations start with the trail. Specific obligations differ substantially, because retention periods, what must be logged, who may see it and how long records of hiring decisions must be kept vary by country, state, sector and sometimes employer size, and they change over time. Treat any period you have heard quoted as the start of a conversation with qualified legal counsel, not as a rule, and check logging depth when comparing [enterprise ATS](/enterprise-ats) options.

What can an audit trail not tell you?

Intent, reasoning, and anything that happened outside the system. The log shows that a recruiter rejected forty candidates on a Tuesday. It cannot show whether the decision was sound. It records that a hiring manager viewed a profile, not what they concluded. Conversations in chat tools, phone calls and hallway decisions leave no trace at all, and those are frequently where the real decision was made. Trails also inherit limits from configuration, so if an integration writes changes under a single service account, every action it takes looks identical no matter which person triggered it. A log nobody reads provides no control either, only the possibility of one. The practical response is to keep decision reasoning in structured places such as scorecards and written notes, giving the trail something with substance to point at rather than bare timestamps.

See how Pitch N Hire handles audit trail on your roles

FAQ

Audit Trail — FAQs

How long should audit logs be retained? +
Long enough to cover the period in which a hiring decision could reasonably be questioned, which is longer than most teams assume. Actual requirements vary by country, state, sector and sometimes employer size, and some overlap with data minimization rules pulling the other way. Set the period with your data protection owner and confirm it with qualified legal counsel rather than accepting a default.
Can a recruiter or administrator delete an audit entry? +
In a properly designed system, no. Entries are written automatically and exposed read-only, and even administrators should be unable to edit them, because a log an insider can rewrite proves nothing. Some products allow bulk purging on a retention schedule, which is a different thing from editing individual records. Ask a vendor directly who can alter or purge log data.
Is an audit trail the same as a candidate activity feed? +
No. An activity feed is a readable summary shown on the record for recruiters, covering the events they care about day to day. An audit trail is the underlying and more complete log, including administrative and security events that never appear on a profile. Feeds are for working, trails are for investigating, and some systems expose only the feed.
Who should be able to read the audit trail? +
A small group, usually system administrators, recruiting operations and whoever handles compliance or security questions. Broad read access turns the log into a monitoring tool for managers watching their teams, which changes behavior and was never its purpose. Restrict it, log access to the log itself where the product allows, and define in advance who can request an extract.
Built for recruiters & hiring teams

See Audit Trail in action

Pitch N Hire unifies sourcing, screening and hiring decisions on one AI-native platform. Book a quick demo on your real roles.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo