Auditability

When someone asks who opened it, the product knows.

That question arrives at a bad moment, from someone who needs an answer today. Casewelt keeps content and security events in one searchable record. The answer comes from the system that made the decision.

In the console

Your organisation’s events, in one searchable place.

The audit screen in the admin console shows when it happened, who did it, what they tried, whether it was allowed, and which file was involved. Records are added to the chain and never edited afterwards, and you can verify that chain yourself at any point.

You can also forward events to your own security monitoring. That copy is useful, but it is a copy: the answer to a question about your content comes from the product record itself.

The Audit screen in the organisation console: a Verify chain button, activity totals, a per-person breakdown of downloads, shares and uploads, and recent events showing when, who, what action and the outcome.

Evidence with context

Record more than “something happened”.

Actor

Know whether the event came from a staff principal, machine principal or external recipient.

Object

Connect the event to the relevant workspace object, file version, share or policy context.

Outcome

Distinguish successful access, explicit policy denial, expiry and revocation-related failures.

Sequence

Keep enough ordering context to reconstruct how the state changed over time.

Delivery

Send selected events to downstream systems through signed webhooks without making the copy the source of truth.

Operations

Treat duplicate webhook deliveries as a normal at-least-once pattern that consumers can deduplicate.

When a screen is not enough

Investigate, then export evidence you can hand over.

Explorer

Search by person, file, version and outcome. Staff, machines and external recipients stay distinguishable.

Investigations

Pin the events that belong to one question. That folder is your working set; it is not yet the sealed package.

Sealed packages

Ask for an evidence export: a signed bundle you download and verify offline. Search results define the candidate scope. The package is a sealed artefact with a defined range.

Operational value

Audit serves ordinary operations as well as incidents.

Security teams need evidence. So do support, compliance and product operations. A structured audit model distinguishes a policy denial from a revoked session, an expired share from a missing file, or a user action from machine automation.

When you need more than a screen, Casewelt builds a sealed evidence package from the forensic record: signed, downloadable, and verifiable offline. Search results define the candidate scope. The package is a sealed artefact with a defined range.

Usage dashboards are a different surface: storage and product activity as daily facts. Export is a document.

When you try it

  1. Search “who opened version 3?” and get staff versus recipient as different actors.
  2. Pin those events into an investigation. Confirm that folder is not yet the sealed package.
  3. Request an evidence export. Open it offline. The console screenshot is not the artefact.
  4. Verify the chain. Then try to “edit” an old event. You should not be able to.
Usage reports → Audit API →

Start with a question

Start with a question your audit team asks.

We can trace the actor, object, version, decision and sequence directly in the product model.

Request a demo