The append-only audit log
A permanent, tamper-resistant record of privileged access — staff impersonation and platform-access grants.
A record you can trust
Snowmass keeps an append-only audit log — a running history of privileged access to your workspace: staff impersonation and platform-access grants and revokes. "Append-only" means entries are added but never edited or deleted. The record only grows, so it can be trusted as an accurate account of that access.
Why append-only matters
A log you can quietly change isn't evidence. By making the audit log write-once, Snowmass ensures that once an action is recorded, no one — not an operator, not an admin, not even during troubleshooting — can rewrite history. The application enforces this: the model refuses any edit or delete to the log, so the record only ever grows.
What it's good for
- Accountability for privileged access — see every time staff impersonation or platform access was granted, used, or revoked, and by whom.
- Dispute resolution — settle "who was in this workspace, acting as whom?" with a durable record instead of memory.
- Compliance — demonstrate a clean chain of privileged-access events when a customer or auditor asks.
Impersonation is fully stamped
When Snowmass staff assist inside your workspace, or an org admin acts on a customer's behalf, the audit log records both identities — the account acting and the true user behind it. Support access is never anonymous; every assisted action is attributable.
Reports vs. audit log
Reports are for operational data you filter and export — service visits, materials, incidents, recalls, runs (see Running reports & exports). The audit log is the narrow, immutable trail of staff impersonation and platform-access grants and revokes. They complement each other: reports tell you what was serviced, the audit log tells you when someone was granted access to the workspace and who acted on whose behalf.
Updated 2026-08-09