FillTrust

How to answer

Can customers access audit logs of activity in their account?

This one is a product question, not a security question, and the honest answer for most young products is no with an offer attached.

A model answerAnswered “no” from your documents

Not as a self-service export today. Every change is recorded with the actor and a timestamp, and we will provide the log for a customer's account on request. A self-service view is on the roadmap.

FillTrust grades an answer like this answered “no” from your documents when your documents support it.

Answered from
Your product documentation, and your feature list.
Evidence to attach
A screenshot of the audit trail in the product, or a link to the documentation page.
Where it is asked
CAIQ v4.0 · LOG-04SIG LiteBespoke vendor questionnaires

Reviewers ask this for a specific reason: their own auditors will eventually ask them to evidence who did what inside your product, and if the answer is that only you can retrieve it, that becomes a dependency on your response times.

Separate recording from access. Most products record more than they expose. If you have an append-only history of changes with an actor and a timestamp, that is the substance of the control, and the gap is only the interface. Saying "recorded in full, retrievable on request, not yet self-service" is precise and it scores far better than a bare no.

Say what is in the record. Who acted, what changed, and when. If you keep the previous value as well as the new one, say so, because that is the difference between a log and a genuine audit trail and it is the thing an auditor is looking for.

Retention matters here too. A customer's audit obligation may run to a year or more. If your history is kept for the life of the account, say that; it is a stronger answer than a number, and it is usually true.

Do not promise a date. "On the roadmap" is understood. A named quarter written into a questionnaire has a way of resurfacing in a renewal conversation.

If the answer is genuinely no, that is still a finished answer rather than a gap: no, activity is not exposed to customers today. Reviewers can accept it, price it into their own controls, or ask for it contractually. What they cannot do anything with is a vague yes that turns out to mean server logs you would have to grep.

For most teams this grades as a documented no, which is the second-best outcome on any questionnaire: a clear answer, drawn from what the product does, with no ambiguity for anyone to discover later.

How this one goes wrong

Specific to this question, not general advice.

  • Answering yes because you keep logs. The question is whether the customer can get them, which is a product feature rather than an infrastructure one.
  • Promising a roadmap date. "On the roadmap" is acceptable; a quarter you then miss becomes a contractual conversation.
  • Forgetting that this is often a requirement rather than a preference for regulated buyers, who may need it for their own audit.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.