Audit trail
A tamper-evident record of every action in your organisation, with a chain you can verify yourself.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
The audit trail records who did what, when and from where: who approved which visitor, who exported a report, who changed a kiosk's settings. It's append-only, and each entry is linked to the one before it, so any change to history shows.
What's recorded
| Kind of action | Examples |
|---|---|
| Sign-ins and access | Sign-ins, failed sign-ins, passkeys added, kiosks paired |
| Visitors | Check-ins, approvals, denials, check-outs, watchlist matches and overrides |
| Viewing personal data | Opening a visitor's record or ID details, viewing photos |
| Exports | Every report and CSV export, with the number of rows |
| Changes | Edits to people, forms, sites, devices, roles, retention and branding settings, with before and after |
| Deletions | Scheduled deletion of ID images and old visits, erasure requests, face templates removed |
| Attendance | Corrected punches, approved timesheets, settings, notices, acknowledgements, consents, face enrolment |
| Ardent access | Any access by Ardent support, with the reason given |
Each entry stores the time, the person or device, the action, what it acted on, the device or app, and the IP address.
How tamper evidence works
- Append-only. Entries can be added, never edited or deleted, by anyone, including Owners and Ardent staff.
- Hash-chained. Each entry stores a cryptographic hash of the entry before it. Changing or removing any entry breaks every link after it.
- Anchored every hour. Once an hour, Agoo records a checkpoint of the chain so far and keeps a copy outside the database. A checkpoint fixes history up to that point, so it can't be quietly rebuilt.
Verify the chain
In Console → Security → Audit trail, choose how far back to check (the last day, week or month, or everything your plan shows) and choose Verify chain. Agoo recalculates every link in that period and compares each hourly checkpoint with its entry. You'll see either a confirmation that the chain is intact, with how many entries and checkpoints were checked, or the first entry where it breaks and why. The check itself is recorded in the trail.
If the chain is ever broken, contact Ardent support at once, and don't change anything until they've looked.
Search and export
Entries are listed newest first, by day, on your organisation's clock. Filter by who acted (a person, device or API key), what happened (one action, or every action on something, such as every visit action), site and dates. Choose Export to download the filtered entries as CSV or Excel for your auditors; the export is itself an audited action. On Pro and Enterprise, you can also read the trail through the API.
The Auditor role can view and export the audit trail without being able to change anything else. See Roles and permissions.
How long it's kept
| Plan | Audit trail kept |
|---|---|
| Free | 7 days |
| Starter | 90 days |
| Growth | 1 year |
| Pro | 3 years |
| Enterprise | Up to 7 years |
The audit trail has its own retention, separate from visitor data. Moving to a lower plan doesn't delete entries: the console and exports show the new plan's period, and older entries are kept, hidden, and come back when you move up. See Retention and deletion.