Scope
This guide covers governance & controls for Decision History & Audit Log. Availability depends on your tenant package, role and configured providers.
Purpose
Explain what changed, who acted and what advice was used.
Keep decision records tamper-resistant and strictly tenant-scoped.
Before you start
Correct tenant and project selected
Required source or provider is available
An accountable owner is identified
Test data can be separated from live activity
Procedure
- Identify the customer, financial, access or publishing consequence involved.
- Keep decision records tamper-resistant and strictly tenant-scoped.
- Assign the minimum required roles and the accountable owner.
- Confirm consent, provider, tenant and approval requirements before activation.
- Inspect audit history and retain the evidence behind important decisions.
- Review access, configuration and exceptions on an agreed operating cadence.
Verify the result
Review change frequency, declined advice and incident context. Confirm that the intended record, state, run or report is visible to another authorised operator and that its next owner is clear.
Completion checkpoint
The capability is in the intended state, evidence is current, exceptions are owned and the next action can be understood without a separate status message.
Controls and limitations
Keep decision records tamper-resistant and strictly tenant-scoped. Predictive, attribution and recommendation outputs support operator judgement; provider and data limitations remain relevant.