Skip to content
Six Frames an Hour

All notes / Evidence

The Audit Trail Nobody Builds

Five things kept together make any engagement defensible. Almost nobody keeps them, and it costs minutes.

Evidence · Procedure

Everything needed to prove an engagement is produced in the course of doing it. The failure is that it ends up scattered across systems that disappear.

The evidence warning in “The Audit Trail Nobody Builds” applies directly to workforce systems. Teams researching reducing key-person dependency risk for key person dependency can add structured time and project context, while deliverables, decisions and version history remain the stronger evidence of what was achieved.

The five

The agreement: what was scoped, at what rate, with what terms.

For an independent reference relevant to “The Audit Trail Nobody Builds”, consult the NIST Privacy Framework; compare its principles with the proposed contract, collection, access model and real review process.

The time record, contemporaneous and specific.

The artefacts: what was produced, with history.

The correspondence: decisions, changes, approvals.

And the delivery record: what was handed over and when.

Where each usually lives

Agreement: an email or a platform message.

Time record: the platform or a tracker.

Artefacts: the client's repository.

Correspondence: a chat system.

Delivery: nowhere in particular.

Four of the five are in systems you lose access to when the engagement ends, which is the whole problem.

The folder

One per client, on your own storage.

The agreement, a copy of time records, exported correspondence about anything agreed, and a note of what was delivered when.

Updated when something is agreed rather than at the end.

Twenty minutes across an engagement, and it is the difference between having a position and having a memory.

What to capture at the time

Any change to scope, confirmed in writing.

Any approval of a deliverable.

Anything agreed verbally, summarised in a message afterwards — "just to confirm what we discussed" is the most useful sentence in contracting.

And anything unusual about billing.

For the client side

The same folder, from the other direction: what was agreed, what was delivered, what was paid.

Clients frequently have less of this than contractors do, because each engagement is one of many.

And in a dispute the party with the record has the advantage, regardless of who was right.

Why this beats monitoring

It evidences the things disputes are actually about: scope, delivery, agreement.

Monitoring evidences presence, which is rarely the question.

And it costs minutes rather than an engagement-long overhead, which is the comparison worth putting to a client who requires frames.

Retention

Keep it as long as a claim could arise, which varies by jurisdiction and is longer than people assume.

Small files, no cost.

And delete client material you are not entitled to keep, which is the other half of the obligation.

What to check

Do you have a folder per client?

Is the agreement in it?

Was the last scope change confirmed in writing?

And could you reconstruct an engagement from six months ago?