Audit Record Editing Limitations
Overview
Audit record editing should be intentionally limited to protect the audit trail.
Metadata vs evidence
| Can be managed | Should remain read-only |
|---|---|
| Notes | Performed by user |
| Tags | Action type |
| Reviewed status | Timestamp |
| Archive status | IP address |
| Investigation comments | Old and new values |
Developer note
If custom code allows editing original audit evidence, it weakens the value of the audit trail. Use separate metadata fields instead.

