Auditability

Who opened the file should be a question the product can answer

If you have to dig through mail and logs to answer an ordinary content question, the useful context never made it into the product.

Audit starts with product identity

A content system already knows the actors, resources and actions that matter. That makes it the natural place to keep the authoritative record of significant events: a share was created, a recipient was verified, a file version was read, an action was denied, or a hold changed state.

The record becomes far more useful when those events share stable identifiers for the organisation, file, version, share and actor.

Sequence explains behaviour

A single access log line rarely explains the whole story. Security and compliance questions often depend on order: the share was created, then used, then revoked, then used again and denied. A searchable event chain can show that progression directly.

This is not just for incidents. Support teams can use the same context to explain why a user cannot access a file, while operations teams can distinguish normal policy enforcement from service failure.

SIEM is a destination, not the source of truth

Forwarding events to a SIEM is valuable because it connects content activity to the organisation’s wider monitoring. But the copy should not become the only record of what the content product itself decided.

Casewelt’s model keeps the product audit authoritative while allowing selected events to leave through signed webhooks. Consumers can store, correlate and alert on those copies without losing the source context.

What the record should answer

A useful audit model should answer the question directly from product identity and event sequence. If the answer depends on reconstructing several downstream systems, the evidence model is already doing too little.