Platform — Audit Trail

Every action. Every user. Every timestamp. The audit trail runs continuously.

Every action taken in HaulageOps is logged automatically — who did it, what they did, and exactly when. Jobs, documents, invoices, access events and role changes. Management can query the history without asking the team.

User identity on every log entryPrecise timestampsExportable recordsMulti-tenant isolation
Job events logged end-to-end
Document upload & access events
Invoice creation, changes & payment
User access and role changes
Exportable for audit preparation
Tenants see only their own records
What gets logged

The audit trail covers every consequential action across all five portals.

The audit log is not a manually-maintained record — it runs automatically in the background whenever a user takes a consequential action in HaulageOps. There is no opt-in, no gap in coverage, and no way for a user to take an action that bypasses the log.

Job events

The complete lifecycle of every job is captured — from creation through assignment, dispatch, status changes, completion, and POD upload. Each event records the acting user, the timestamp, and the relevant job detail.

  • Job created — by which user, when
  • Job assigned to driver or subcontractor
  • Status changes: en route, on site, loaded, complete
  • POD uploaded — including the uploading user
  • Job edited or cancelled — with the reason if entered

Document events

Every document stored, accessed, or deleted in HaulageOps is captured in the audit log. This includes delivery dockets, POD photographs, driver licences, vehicle registrations, contracts, and insurance certificates.

  • Document uploaded — by which user to which record
  • Document accessed — who viewed the file and when
  • Document updated or replaced — version history
  • Expiry date changes — who modified and when

Invoice and billing events

Every step in the invoice lifecycle is logged — from the initial draft through to payment received. Finance can query whether an invoice was sent, when, and what happened to its status, without calling dispatch.

  • Invoice created and which jobs it covers
  • Invoice sent to client
  • Status changed: draft, sent, paid, overdue, voided
  • Rate applied and under which contract
  • Payment received event from Xero webhook

Access and role events

User login events, role assignments, and permission changes are captured. If a user's access level is changed — or if a new user is added or removed — it appears in the audit log with the administrator who made the change.

  • User login and session events
  • Role assigned or changed
  • New user created or user deactivated
  • Portal access granted or revoked
Structure of each log entry

Who, what, and when — on every single record.

Every entry in the HaulageOps audit log contains three pieces of information: the user identity of the person who took the action, a description of what the action was, and the precise timestamp at which it occurred. Together, these three fields make the log usable for investigation, dispute resolution, and audit preparation.

  • Who: the authenticated user identity — not a role name, the actual user account
  • What: a specific description of the action taken and the record it affected
  • When: a precise timestamp — date and time, not just a date

Management can query this history directly from the HaulageOps reporting interface without needing to ask the operations team. “Who changed the rate on job 4821 and when?” is a query, not an investigation.

Audit log — job history view
Job #4821Export to CSV
TimestampUserAction
09:14Sarah KJob createdclient Apex Civil
09:22Sarah KDriver assignedMike T
11:03Mike T (driver app)Status: En route
13:47Mike TPOD uploaded2 photos
14:02Sarah KJob marked complete

Each row shows exact timestamp, user, and action detail.

Chain of responsibility

Demonstrable due diligence — not a verbal claim.

Under Chain of Responsibility obligations applicable in the Australian market, operators must be able to demonstrate active management of safety-relevant activities — not simply state that processes exist. An audit trail that runs automatically, covers all consequential actions, and can be queried and exported is a direct piece of that evidence.

The problem with verbal instructions

When dispatch is managed through phone calls, WhatsApp messages, and verbal instructions, the audit trail is the person's memory. That is not evidence of a managed process — it is a gap in your due diligence record.

What a system audit log provides

A continuous, automated, tamper-resistant log shows that your operations are managed through a documented system — not verbal agreements. Every assignment, status update, and document upload has a record.

Exportable for audit preparation

Audit logs in HaulageOps can be exported for preparation purposes. If you receive an inquiry from a regulator, client, or insurer, you can produce a structured record of activity across the relevant time period without reconstructing it from memory.

Audit log — export and query view
From — dateTo — dateJobs / Invoices / Documents / AccessUser
TimestampUserAction
09:14Sarah KJob created
09:22Sarah KDriver assigned
11:03Mike T (driver app)Status: En route
847 records matching the current filterExport to CSV
Multi-tenant isolation

Your audit records are yours. No cross-tenant visibility.

HaulageOps is a multi-tenant SaaS platform — meaning multiple operating companies run on the same infrastructure. Audit records are strictly isolated by tenant. An operator can only see their own audit history. There is no mechanism for one tenant's data to appear in another's audit log.

This isolation applies equally to the export function. When you export audit records, you export your own records only. This is enforced at the database query level, not just the interface layer.

  • Tenant isolation enforced at the data layer
  • Exports contain only your own organisation's records
  • No cross-tenant audit record access under any role
  • Subcontractor actions visible within your job records only
Related platform features

The audit trail connects compliance across the platform.

Compliance & Audit

The audit trail is one part of the broader compliance toolkit — alongside document expiry tracking, break and rest records, and contract management. See how it connects.

Compliance overview

Document Management

Every document upload, access, and expiry event is captured in the audit log. Document management and the audit trail operate as a single evidence system.

Document management

Reporting & Analytics

Management reporting surfaces operational and financial data on top of the same underlying record set that feeds the audit trail — giving management a consistent view of the business.

Reporting & analytics
Frequently asked questions

Audit trail — common questions.

How far back does the audit trail go?

The audit trail retains the full history of your account from the point HaulageOps was set up for your organisation. There is no rolling deletion of older records within the standard retention period. If you have specific retention requirements — for regulatory, insurance, or contractual purposes — discuss these during onboarding.

Can audit records be deleted or altered?

No. Audit log entries are write-once records. No user — including an administrator — can delete or alter an audit log entry through the HaulageOps interface. This is intentional: the value of an audit trail depends on it being tamper-resistant. If a user takes an action that turns out to be incorrect, the corrective action also appears in the log — both entries are preserved.

Who can see the audit trail?

Access to the audit log is controlled by RBAC. By default, management-level users can query the full audit history. Dispatch and driver roles see only the audit information relevant to their own actions and assigned jobs. You can configure the access tiers during setup to match your internal structure.

Can we export the audit trail for an external audit or inquiry?

Yes. The audit log can be exported in structured format — filtered by date range, event type, or user. The export contains only your organisation's records. This is designed to support audit preparation, insurance inquiries, client reviews, and regulatory requests without requiring you to reconstruct information manually.

Does the audit trail cover actions taken on the driver mobile app?

Yes. Actions taken through the driver mobile app — status updates, POD uploads, break records — are logged to the same audit trail as actions taken in the Admin Panel. The user identity in these log entries is the authenticated driver account, not a generic device identifier.

Does the audit trail cover subcontractor portal actions?

Yes. When a subcontractor accepts or declines a job through the Subcontractor Portal, that action is logged with the subcontractor's user identity and timestamp. These entries appear in your organisation's audit log alongside all other job events, giving you a complete picture of the assignment lifecycle.

Replace verbal instructions with a documented audit record.

See how HaulageOps logs every job, document, invoice, and access event automatically — with user identity and timestamp on every entry.