Skip to main content
intelID intelligence platform logo
Menu

Audit logging

Search audit logs: an unalterable record of who searched, when and why

The question that arrives months later is never what did you find. It is who ran this search, and on what basis.

The problem this answers

An organisation carries responsibility for searches run in its name. When a client, a regulator or a data provider asks about one, the answer has to come from a record made at the time, not from a recollection assembled afterwards.

Where searching is spread across several provider accounts, there is no single record. There are several partial ones in different formats, and reconstructing an enquiry from them is the work nobody has time for.

What the search returns

  • The user who ran the search, as a named, verified individual.
  • The timestamp of the query.
  • The authorised purpose declared before results were returned.
  • The sources queried in that enquiry.
  • The search terms used, so the enquiry can be reconstructed rather than described.

When it is used

  • Responding to a privacy complaint or an enquiry from the Office of the Privacy Commissioner.
  • Supervisory review inside a firm, where a partner or manager is accountable for what staff searched.
  • Data provider audits, where access under a licence has to be evidenced.
  • Supporting an affidavit of reasonable enquiry, where the record of what was searched matters as much as the result.

What it does not establish

  • An audit log records that a purpose was declared. It does not make an improper purpose proper.
  • It is a record of enquiry activity, not a case file or a work product archive.

The limits on the enquiry

  • The log cannot be edited by the user who created the entry.
  • Logs are retained and can be produced where a search is questioned, in line with the retention position set out in our privacy policy.
  • Access to logs within an organisation is governed by role.

The statutory position is set out in full on the compliance page.

Who may access it

  • Account administrators can review activity for their organisation. Individual users see their own.

How intelID consolidates the result

Because the sources are queried through one platform, one entry covers the whole enquiry instead of five partial records across five provider accounts.

The declaration, the query and the sources sit in the same entry, so the basis and the action are never separated.

What you pay is the monthly subscription plus the searches you run, set out on the pricing page. Every integrated source and its legal basis is listed on the data sources page.

Questions about audit logging

Can a user delete or edit their own search record?

No. Entries cannot be altered by the user who created them.

Can I produce the log if a client or regulator asks?

Yes. That is what it exists for. Account administrators can review and produce activity for their organisation.

How long are logs retained?

Logs are retained in line with the retention position set out in our privacy policy, which is written to support later enquiry rather than to minimise the record.

Request access to intelID

Tell us who you are and what you need to search, and we will set up your account. Verification is part of the process and usually straightforward. Most accounts are verified and issued within 2 business days.