AUDIT ARCHITECTURE
Audit Logs Overview
Understand how True Care System records, classifies, displays, and preserves audit evidence.
Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.
True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.
Purpose
The Audit Logs workspace records security-relevant, privacy-relevant, operational, and administrative events across the True Care System platform. Each event is connected to a Provider scope and may also reference a user, actor, target user, Individual, employee, entity, route, request, device, or support session.
Core Audit Principles
| Field | Function |
|---|---|
| Provider isolation | Audit results must remain limited to the authenticated Provider scope unless a separately authorized platform role is used. |
| Identity accountability | The system distinguishes the authenticated user, acting identity, target user, and affected record. |
| Event classification | Module, action, event type, severity, and status make events searchable and reviewable. |
| Change evidence | Update events may preserve old values and new values for integrity review. |
| Request evidence | IP address, HTTP method, route, request ID, browser, device, operating system, and user agent support reconstruction. |
| Support traceability | Support ticket and impersonation session identifiers connect technical access to approved support workflows. |
Event Lifecycle
- Action occurs.
A user or system process performs a view, create, update, delete, login, export, support, or other auditable action.
- Context is captured.
The system records Provider, identity, entity, request, device, status, and event metadata.
- Event is classified.
The action is assigned a module, action, event type, severity, and status.
- Authorized review occurs.
Compliance, security, or administrative users search and inspect the event.
- Evidence is preserved.
Exports, investigations, retention, and incident-response actions follow Provider policy.

