Who did what, when, from where: the answer is on record
Every action taken in GSE-Web, by a person, an AI assistant or an integration, leaves a line no one can erase, not even the software. The day you are asked to account for something, you open the journal.
Editable
By no one
Retention
400 days to unlimited
AI assistants
Tracked
400
days of retention on shared hosting, unlimited on dedicated hosting
0
lines the software can modify or erase
1
seal per day, chained to the previous one
100%
of AI assistant calls recorded in the journal
A black box for your stock
You work as usual. In the background, the journal records what happened and keeps it safe.
Who, what, when, from where.
You act
A stock issue, a price change, a lot release, a sign-in, an export: every write, every denied access and every sensitive read goes through the journal.
The journal records
It keeps the author, the time, the IP address, the device and app version, the outcome (success, denied, failed) and, for important actions, the before, the after and the reason.
You find it
On the day of an audit, a dispute or a lot recall, you filter by period, person or action, and the answer is there, dated and signed by its author.
An aircraft's black box
In an aircraft, the black box records everything that happens in the cockpit, and not even the pilot can erase it. The GSE-Web audit journal follows the same rule : it is not an instruction given to the software, it is the database itself that refuses any change to or deletion of a line.
Nothing to configure
The journal runs from day one. All that remains is knowing where to read it.
Open the Audit journal
The screen is in the ADMIN section of the menu. It is reserved for your organization's administrator and included from the ENTERPRISE plan.
Filter, open, export
Filter by period, action, outcome or channel (application, AI assistant, scheduled task). Open a line to see its detail: IP address, browser, device, before and after.
No one can erase it. Not a user, not an administrator, not the software itself: the database refuses any change to or deletion of a line. Only the retention period removes the oldest lines, and that purge leaves a trace of its own.
What about the host? When the platform team works on your organization or reads your journal, the line appears in your journal, under their name.
Four uses, one journal
Audit journal
The administrator's screen
Each line answers five questions: when, who, what, on what, with what outcome. The detail adds the IP address, the browser, the platform and its version, the device and, for a business action, the value before and after. Your organization's retention period is shown on the screen.
Exports are in CSV over a period of up to 400 days. The export itself is recorded in the journal: you know who took out what, and when.
Lot life record
Quality audits, pharmacy, food industry
The lot record brings together the full history of its statuses (quarantine, blocked, available), with the name, date and reason for each change, and its quality inspections: sampling, verdict, authors. Each movement keeps two dates, the one entered and the one recorded, so backdating can be spotted.
Releasing a blocked lot requires a reason, as does adjusting the quantity of a lot that is not available. Without a reason, the software refuses.
Lot recall
Where did the goods go?
A supplier reports a defective lot, a health alert comes in: the recall lists every third party, order form or customer order that received this lot, with quantities and dates. You know who to notify, and you export it for your file.
Viewing a recall is a sensitive read: it is itself recorded in the journal.
AI assistants and API keys
Machines have a name too
An API key identifies an integration or an AI agent. It acts on behalf of an account, bounded by a role that can restrict it to read-only, expires on the chosen date and can be revoked in one click. It is shown only once. Every call made with it, reads included, carries its name in the journal.
An AI assistant connected to GSE-Web is recorded at every tool call, read or write: “Claire's assistant” and “Claire” are two distinct actors in the journal.
What the software guarantees
A trail is only worth something if no one can touch it up. GSE-Web does not rely on goodwill: it forbids it.
Immutable by the database
The application simply has no right to modify or erase a journal line. Not a bug, not an administrator account can rewrite the past. The same applies to the history of stock movements, lot statuses and quality inspections.
The action and its trace, together
For actions that commit you (a status, an amount, a right, a setting, an account, a reason), the journal line is written at the same time as the action. If it cannot be written, the action is cancelled: no action without a trace.
Daily seals
Every night, the past day receives a digital fingerprint (SHA-256) of all its lines, chained to the previous day's. A line modified, removed or added afterwards is detected on verification.
Nothing slips through the net
Every write, every denied access and every sensitive read (exports, user list, lot recall) is recorded automatically, including for features added tomorrow. Passwords and secrets are never copied.
Everyone signs under their own name
A person, an AI assistant, an integration, the platform team: the journal never confuses them. That is what lets you answer “who?” without hesitation.
The journal tells apart
Users: sign-ins, failed sign-ins, sign-outs, two-factor authentication, password changes, and everything they do next.
AI assistants: every tool call, with the assistant's name, the user on whose behalf it acts, the duration and the outcome.
Integrations using an API key: every call carries the key used, reads included. The key can never do more than the account that holds it.
The platform team: when it works on your subscription, your settings or your data, or reads your journal, the line is on your side, under its name.
Signed in as someone else? Both names.
When support signs in as a user to help them, the journal keeps both names: the account used and the real person behind the screen.
Exportable, and the export leaves a trace
A period, a filter, a click: the journal goes out as CSV for your auditor or your quality file. An export is a sensitive read, so it is itself recorded in the journal.
The words of traceability
Six terms you will come across on screen, explained without jargon.
Audit journal
The dated list of everything that happened in your organization: who, what, when, from where, with what outcome.
Immutable
Cannot be modified or erased. A line written to the journal stays there, as is, until the end of its retention period.
Reason
Why a sensitive action was taken, entered at the time of the action. Releasing a blocked lot without a reason is refused.
Lot life record
The whole story of a lot on one page: receipt, inspections, status changes with their author and reason.
Lot recall
The list of everyone who received a given lot, with quantities and dates. What you need at hand during an alert.
Seal
The digital fingerprint of one day of the journal, chained to the previous day's. If a line changes, the fingerprint no longer matches.
What the journal keeps
From the most routine to the most sensitive, what GSE-Web records in your organization's journal.
| Event | What the journal keeps | |
|---|---|---|
| Access | ||
| Sign-ins and denied access | Sign-in, failure, sign-out, two-factor authentication, attempts refused for lack of rights. | |
| Actions | ||
| Writes and sensitive reads | Every creation, change or deletion, and every sensitive read: author, time, workstation, outcome. | |
| Actions that commit you | Value before and after, and the reason when one is required: lot statuses, counts, prices, rights, settings, accounts. | |
| Machines | ||
| AI assistants | Every tool call, read or write: tool, user represented, duration, outcome. | |
| Integrations using an API key | Creation and revocation of the key, then every call made with it. Never the secret. | |
An auditor asks,
you show them
Quality audit, customer inspection, dispute with a supplier: the journal gives you a dated, signed and verifiable answer, instead of a recollection.
400 days of retention on shared hosting, unlimited on dedicated hosting (CORPORATE plan). When the period expires, the purge is itself recorded in the journal.
Chained daily seals: each day's fingerprint can be verified on demand; a line modified, removed or inserted afterwards is flagged.
Two dates per movement: the one the operator entered and the one when the server received it. A backdated movement stands out.
MCP server: an administrator's AI assistant reads the journal in read-only mode, and that read leaves a line of its own. In a school, the journal is never served to assistants, to protect students' data.
"occurredAt": "2026-10-08T14:32:07Z",
"source": "api",
"actorName": "Claire Martin",
"impersonatorName": null,
"actorIp": "203.0.113.24",
// what, on what, and why
"action": "INVENTORY_LOT_STATUS_CHANGED",
"entityType": "lot",
"details": {
"lotNumber": "L2026-0142",
"from": "blocked",
"to": "available",
"notes": "Counter-analysis compliant"
},
// with what outcome
"outcome": "success"
“Who changed this stock?”
The answer is already on record.
The audit journal is included from the ENTERPRISE plan. Show us what your auditor asks for: we will look together at how GSE-Web answers it.
Frequently asked questions
Can a line of the audit journal be modified or deleted?
No. The database refuses the software itself any change to or deletion of a line: not a user, not an administrator, not a bug can rewrite the past. Lines only leave at the end of their retention period, and that purge is itself recorded in the journal, or with the complete deletion of the organization at its request.
How long is the journal kept?
400 days on shared hosting, with no limit on dedicated hosting (CORPORATE plan). The period that applies to your organization is shown on the Audit journal screen.
Are AI assistants' actions tracked?
Yes, all of them. Every tool call by an AI assistant connected to GSE-Web, read or write, is recorded in the journal with the assistant's name, the user on whose behalf it acts, the duration and the outcome. Integrations using an API key are tracked the same way, call by call.
Is the audit journal included in my plan?
The Audit journal screen and API keys are included from the ENTERPRISE plan, at €1,200 excl. tax per year for 10 users. The history of stock movements, with the author and date of each movement, is available on every plan.
Is GSE-Web enough to obtain a certification (ISO 9001, HACCP, good manufacturing practice)?
GSE-Web does not certify your organization and does not itself hold these certifications. It gives you the evidence an auditor asks for: who did what and when, the reason for sensitive actions, the life record and recall of a lot, and a trail no one can touch up. Certification remains a matter for your certification body.