Auditability

Answering “who opened the file?” from the product record

If an important content question requires searching inboxes and application logs, the product has already lost useful context.

Audit starts with product identity

A content system already knows the actors, resources and actions that matter. That makes it the natural place to keep the authoritative record of significant events: a share was created, a recipient was verified, a file version was read, an action was denied, or a hold changed state.

The record becomes far more useful when those events share stable identifiers for the organisation, file, version, share and actor.

Sequence explains behaviour

A single access log line rarely explains the whole story. Security and compliance questions often depend on order: the share was created, then used, then revoked, then used again and denied. A queryable event chain can show that progression directly.

This is not just for incidents. Support teams can use the same context to explain why a user cannot access a file, while operations teams can distinguish normal policy enforcement from service failure.

SIEM is a destination, not the source of truth

Forwarding events to a SIEM is valuable because it connects content activity to the organisation’s wider monitoring. But the copy should not become the only record of what the content product itself decided.

Casewelt’s model keeps the product audit authoritative while allowing selected events to leave through signed webhooks. Consumers can store, correlate and alert on those copies without losing the source context.

What the record should answer

A useful audit model should answer the question directly from product identity and event sequence. If the answer depends on reconstructing several downstream systems, the evidence model is already doing too little.