Who Can Modify Audit Record Metadata?
Overview
Only trusted roles should modify audit record metadata or perform archive/purge actions.
Recommended permission split
| Permission type | Recommended access |
|---|---|
| View logs | Selected managers and admins. |
| Add notes/tags | Admins, security, compliance, support leads. |
| Archive logs | Admins and compliance roles. |
| Purge logs | System owner or highly trusted admins only. |
| API key management | Admins and integration owners only. |
Testing tip
Always test permissions with a real non-admin role. Do not test everything only with the super admin account.

