Governance and control
Audit trail and decision records
What the audit trail records for every conversation and every change, who can see it, how long it is kept, how it is exported for a dispute or a regulator, and how it is protected.
On this page
When a customer disputes what they were told, or a regulator asks how an outcome was reached, you need to show what the agent looked up, where each fact came from, which of your rules applied, and why it did what it did. The audit trail records exactly that, for every action in every conversation, with the time of each step. It also records who in your organisation, and at Telonic, viewed or changed anything, so you can answer "what happened, and why?" with evidence rather than recollection.
What is recorded for every conversation
| Record | What it holds | Example |
|---|---|---|
| Actions | Every lookup, every change written to your systems, every message sent, every handover | "Reservation HTL-48213 updated: arrival moved to Friday" |
| Sources | The system record or document behind each fact the agent gave | "Policy wording, motor comprehensive, section 4.2" |
| Rules and triggers | Each limit checked and each escalation trigger that fired | "Limit: date change permitted on flexible rate, no fee" |
| Stated reason | The agent's own short explanation of why it took each step | "Customer asked to change arrival date; rate permits change without charge" |
| Time | The date and time of each step | "Tue 14 May, 21:14:05" |
| Consent | The caller's answer to the recording consent question | "Consent to record: given" |
| Approvals | Who approved an action held at an approval gate, and when | "Cancellation fee waiver approved by duty manager, L. Farouk" |
| Outcome | Resolved, still open or handed to your team, with the brief if handed over | "Handed to complaints team" |
Figures such as amounts and dates are inserted into the agent's replies directly from your systems, not retyped by the model. The audit trail shows which record each one came from.
Access and change logs
The audit trail covers people as well as agents. Every time someone views a customer record, exports data, changes a control, approves a change or merges two records, it is logged with who did it and when.
Access by Telonic staff is logged in the same way. It is limited to named engineers, from the UAE or your chosen country, for a limited time. In your own cloud account or on your own premises, each access also needs your approval.
Who can see the audit trail
Access to the audit trail is set by role, like everything else in the console (the Telonic web application your team uses). Typically, compliance, risk and operations leads can see full audit trails, and team members see the conversations their role needs. Viewing the audit trail is itself logged.
How long the audit trail is kept
You set how long the audit trail is kept, in line with your own policy and the regulations that apply to you. It can be kept for a different period from conversation content.
If your policy does not allow conversation content to be stored, a content-free audit record is still kept for the period you set. It records the actions, sources, triggers and outcomes of each conversation, without the words that were said. You can still show what the agent did and why, without holding the content.
Exporting for a dispute or a regulator
An authorised person can export the audit trail for a single conversation, for one customer, or for a set of conversations, in a standard format your team can open and share. This is how you respond to a customer complaint, a dispute, an internal investigation or a regulator's request.
Personal information is redacted (removed or masked) in exports by default. Where a dispute or a regulator's request needs the full record, a person whose role allows it can export it with personal information included. That export, who made it and why, is logged. See Personal information redaction.
How the audit trail is protected
The audit trail is kept in write-once, append-only storage (storage where new entries can be added but existing entries cannot be edited or removed), following standard practice for audit records. Nobody can alter an entry, including your administrators and Telonic's engineers. Entries are deleted only when the retention period you set ends, and deletion is itself recorded.
Like all stored data, the audit trail is encrypted with AES-256 (the Advanced Encryption Standard, using 256-bit keys) and held in the region you chose. See Storage, retention and deletion.
The technical detail
| Question | Answer |
|---|---|
| What is logged per conversation? | Every action, the source behind each fact, each rule or trigger applied, the agent's stated reason and the time of each step |
| Are changes to controls logged? | Yes. Every change is logged with who requested it, who approved it, when it went live, and the version before it |
| Is the agent's activity visible in our own systems? | Yes. The agent acts in your systems through its own account, so its changes also appear in your systems' own history and logs, attributed to that account |
| Can entries be edited or deleted? | Entries cannot be edited. They are deleted only at the end of the retention period you set, and the deletion is recorded |
| What is kept if content storage is off? | A content-free audit record: actions, sources, triggers and outcomes, for the period you set |
| Where is it stored? | In your deployment, in your chosen region, encrypted |
In practice
Sahel Crest Properties, a Dubai developer, receives a complaint from a buyer, Tariq. He says the agent told him in March that his handover would happen in June. It is now August.
- The customer care manager opens Tariq's record and filters for conversations about handover.
- The audit trail for his March conversation shows the agent looked up the project's construction status in the developer's system. It told him the project had reached its final milestone, and that his handover date would be confirmed by the handover team.
- It shows no date was given, and records the commitment: the handover team to confirm a date by 31 March.
- The commitment record shows the handover team confirmed a September date on 29 March, by email.
- The manager exports both conversations, with personal information redacted, for the complaints file, and calls Tariq with the facts in front of her.
What your team controls
- How long the audit trail is kept, including when content storage is off.
- Who in your organisation can see audit trails and who can export them.
- Who can export records with personal information included.