🔏 Traceability · Audit journal

Who did what, when, from where: the answer is on record

Every action taken in GSE-Web, by a person, an AI assistant or an integration, leaves a line no one can erase, not even the software. The day you are asked to account for something, you open the journal.

Editable

By no one

Retention

400 days to unlimited

AI assistants

Tracked

Audit journal
Live

400

days of retention on shared hosting, unlimited on dedicated hosting

0

lines the software can modify or erase

1

seal per day, chained to the previous one

100%

of AI assistant calls recorded in the journal

In a nutshell

A black box for your stock

You work as usual. In the background, the journal records what happened and keeps it safe.

Who, what, when, from where.

1

You act

A stock issue, a price change, a lot release, a sign-in, an export: every write, every denied access and every sensitive read goes through the journal.

“Lot L2026-0142 released by Claire Martin, reason: counter-analysis compliant.”
2

The journal records

It keeps the author, the time, the IP address, the device and app version, the outcome (success, denied, failed) and, for important actions, the before, the after and the reason.

People, AI assistants, integrations: each under its own name
3

You find it

On the day of an audit, a dispute or a lot recall, you filter by period, person or action, and the answer is there, dated and signed by its author.

“Who changed this stock?” is no longer debated: it is read.
📋

An aircraft's black box

In an aircraft, the black box records everything that happens in the cockpit, and not even the pilot can erase it. The GSE-Web audit journal follows the same rule : it is not an instruction given to the software, it is the database itself that refuses any change to or deletion of a line.

Getting started

Nothing to configure

The journal runs from day one. All that remains is knowing where to read it.

1

Open the Audit journal

The screen is in the ADMIN section of the menu. It is reserved for your organization's administrator and included from the ENTERPRISE plan.

Menu › ADMIN › Audit journal
2

Filter, open, export

Filter by period, action, outcome or channel (application, AI assistant, scheduled task). Open a line to see its detail: IP address, browser, device, before and after.

No one can erase it. Not a user, not an administrator, not the software itself: the database refuses any change to or deletion of a line. Only the retention period removes the oldest lines, and that purge leaves a trace of its own.

What about the host? When the platform team works on your organization or reads your journal, the line appears in your journal, under their name.

Four uses, one journal

Audit journal

The administrator's screen

ADMIN › Audit journal › Period · Action · Outcome · Channel › Event detail

Each line answers five questions: when, who, what, on what, with what outcome. The detail adds the IP address, the browser, the platform and its version, the device and, for a business action, the value before and after. Your organization's retention period is shown on the screen.

Exports are in CSV over a period of up to 400 days. The export itself is recorded in the journal: you know who took out what, and when.

Lot life record

Quality audits, pharmacy, food industry

Lot record › Status history · Quality inspections

The lot record brings together the full history of its statuses (quarantine, blocked, available), with the name, date and reason for each change, and its quality inspections: sampling, verdict, authors. Each movement keeps two dates, the one entered and the one recorded, so backdating can be spotted.

Releasing a blocked lot requires a reason, as does adjusting the quantity of a lot that is not available. Without a reason, the software refuses.

Lot recall

Where did the goods go?

Lot record › Lot recall › CSV export

A supplier reports a defective lot, a health alert comes in: the recall lists every third party, order form or customer order that received this lot, with quantities and dates. You know who to notify, and you export it for your file.

Viewing a recall is a sensitive read: it is itself recorded in the journal.

AI assistants and API keys

Machines have a name too

ADMIN › API keys › New key › Label · Acts on behalf of · Role · Expires on

An API key identifies an integration or an AI agent. It acts on behalf of an account, bounded by a role that can restrict it to read-only, expires on the chosen date and can be revoked in one click. It is shown only once. Every call made with it, reads included, carries its name in the journal.

An AI assistant connected to GSE-Web is recorded at every tool call, read or write: “Claire's assistant” and “Claire” are two distinct actors in the journal.

Safeguards

What the software guarantees

A trail is only worth something if no one can touch it up. GSE-Web does not rely on goodwill: it forbids it.

Immutable by the database

The application simply has no right to modify or erase a journal line. Not a bug, not an administrator account can rewrite the past. The same applies to the history of stock movements, lot statuses and quality inspections.

The action and its trace, together

For actions that commit you (a status, an amount, a right, a setting, an account, a reason), the journal line is written at the same time as the action. If it cannot be written, the action is cancelled: no action without a trace.

Daily seals

Every night, the past day receives a digital fingerprint (SHA-256) of all its lines, chained to the previous day's. A line modified, removed or added afterwards is detected on verification.

Nothing slips through the net

Every write, every denied access and every sensitive read (exports, user list, lot recall) is recorded automatically, including for features added tomorrow. Passwords and secrets are never copied.

The actors

Everyone signs under their own name

A person, an AI assistant, an integration, the platform team: the journal never confuses them. That is what lets you answer “who?” without hesitation.

The journal tells apart

Users: sign-ins, failed sign-ins, sign-outs, two-factor authentication, password changes, and everything they do next.

AI assistants: every tool call, with the assistant's name, the user on whose behalf it acts, the duration and the outcome.

Integrations using an API key: every call carries the key used, reads included. The key can never do more than the account that holds it.

The platform team: when it works on your subscription, your settings or your data, or reads your journal, the line is on your side, under its name.

🔏

Signed in as someone else? Both names.

When support signs in as a user to help them, the journal keeps both names: the account used and the real person behind the screen.

🌐

Exportable, and the export leaves a trace

A period, a filter, a click: the journal goes out as CSV for your auditor or your quality file. An export is a sensitive read, so it is itself recorded in the journal.

Vocabulary

The words of traceability

Six terms you will come across on screen, explained without jargon.

Audit journal

The dated list of everything that happened in your organization: who, what, when, from where, with what outcome.

Immutable

Cannot be modified or erased. A line written to the journal stays there, as is, until the end of its retention period.

Reason

Why a sensitive action was taken, entered at the time of the action. Releasing a blocked lot without a reason is refused.

Lot life record

The whole story of a lot on one page: receipt, inspections, status changes with their author and reason.

Lot recall

The list of everyone who received a given lot, with quantities and dates. What you need at hand during an alert.

Seal

The digital fingerprint of one day of the journal, chained to the previous day's. If a line changes, the fingerprint no longer matches.

What is recorded

What the journal keeps

From the most routine to the most sensitive, what GSE-Web records in your organization's journal.

Event What the journal keeps
Access
Sign-ins and denied access Sign-in, failure, sign-out, two-factor authentication, attempts refused for lack of rights.
Actions
Writes and sensitive reads Every creation, change or deletion, and every sensitive read: author, time, workstation, outcome.
Actions that commit you Value before and after, and the reason when one is required: lot statuses, counts, prices, rights, settings, accounts.
Machines
AI assistants Every tool call, read or write: tool, user represented, duration, outcome.
Integrations using an API key Creation and revocation of the key, then every call made with it. Never the secret.
For your audits

An auditor asks,
you show them

Quality audit, customer inspection, dispute with a supplier: the journal gives you a dated, signed and verifiable answer, instead of a recollection.

400 days of retention on shared hosting, unlimited on dedicated hosting (CORPORATE plan). When the period expires, the purge is itself recorded in the journal.

Chained daily seals: each day's fingerprint can be verified on demand; a line modified, removed or inserted afterwards is flagged.

Two dates per movement: the one the operator entered and the one when the server received it. A backdated movement stands out.

MCP server: an administrator's AI assistant reads the journal in read-only mode, and that read leaves a line of its own. In a school, the journal is never served to assistants, to protect students' data.

audit_list_events — read-only
// who, when, from where
"occurredAt": "2026-10-08T14:32:07Z",
"source": "api",
"actorName": "Claire Martin",
"impersonatorName": null,
"actorIp": "203.0.113.24",

// what, on what, and why
"action": "INVENTORY_LOT_STATUS_CHANGED",
"entityType": "lot",
"details": {
  "lotNumber": "L2026-0142",
  "from": "blocked",
  "to": "available",
  "notes": "Counter-analysis compliant"
},

// with what outcome
"outcome": "success"

“Who changed this stock?”
The answer is already on record.

The audit journal is included from the ENTERPRISE plan. Show us what your auditor asks for: we will look together at how GSE-Web answers it.

Frequently asked questions

Can a line of the audit journal be modified or deleted?

No. The database refuses the software itself any change to or deletion of a line: not a user, not an administrator, not a bug can rewrite the past. Lines only leave at the end of their retention period, and that purge is itself recorded in the journal, or with the complete deletion of the organization at its request.

How long is the journal kept?

400 days on shared hosting, with no limit on dedicated hosting (CORPORATE plan). The period that applies to your organization is shown on the Audit journal screen.

Are AI assistants' actions tracked?

Yes, all of them. Every tool call by an AI assistant connected to GSE-Web, read or write, is recorded in the journal with the assistant's name, the user on whose behalf it acts, the duration and the outcome. Integrations using an API key are tracked the same way, call by call.

Is the audit journal included in my plan?

The Audit journal screen and API keys are included from the ENTERPRISE plan, at €1,200 excl. tax per year for 10 users. The history of stock movements, with the author and date of each movement, is available on every plan.

Is GSE-Web enough to obtain a certification (ISO 9001, HACCP, good manufacturing practice)?

GSE-Web does not certify your organization and does not itself hold these certifications. It gives you the evidence an auditor asks for: who did what and when, the reason for sensitive actions, the life record and recall of a lot, and a trail no one can touch up. Certification remains a matter for your certification body.