Blog

How to prove a document decision: audit trail, versions, approvals and evidence

Finishing a document process is not enough; you have to prove how the decision was reached. What an evidence pack must answer, why proof falls apart when it lives in several tools, and what a governed dossier records by itself.

Dossier timeline ending in an evidence package with documents, approvals and history.

You prove a document decision by showing five things at once: which documents existed when the decision was taken, which version of each one was seen, who approved and in what order, which exceptions were handled, and which operation was carried out at the end. In a document process, finishing the work is not enough. The organisation needs to be able to reconstruct how it reached the decision, without relying on the memory of whoever was there.

That difference is what separates storage from governance. Keeping files is easy. Proving a decision requires the story of the work to have been recorded while it happened, not reassembled when somebody asks for it.

Why proof fails

When the decision lives in several tools, the evidence is fragmented. The file is in a shared folder. The approval is in an email. The decisive comment was made on a call. The final version replaced the previous one. The expiry date was checked by somebody, but nobody knows when.

None of this is the tools' fault. A SharePoint library keeps versions and permissions very well. An Excel sheet is an excellent checklist. Email is a reasonable record of a conversation. The problem is that none of them knows it is part of the same decision.

Day to day, this appears to work. In an audit, an investigation or a dispute, the team has to reconstruct the story from fragments. Reconstruction is expensive and fragile, and the fragility shows at exactly the moment the proof is needed most.

What good evidence must contain

A document evidence pack must answer objective questions:

  • Which process created this dossier, and under which rules?
  • Which documents were mandatory?
  • Which files were delivered, when, and which were replaced?
  • Which data was extracted, and who confirmed it?
  • Who approved, rejected or returned — and in what order?
  • Was there a quality review? What was corrected?
  • Was any document expired?
  • Which external operation was called, and what came back?
  • What state was the dossier in at the moment of each decision?

Evidence is not just a technical log: it is the verifiable operational narrative. A log says what the system did; evidence says what the organisation decided, on what basis and by whom.

A technical log Evidence
Speaks of events: requests, errors, writes Speaks of decisions: deliveries, approvals, exceptions
Read by whoever operates the system Read by an auditor, a customer or a court
Proves that something ran Proves what was decided, by whom and against which version
Lives outside the work Is born from the work itself

Why the dossier helps

A governed dossier brings documents, states, decisions, review and history together in the same working object. That lets the evidence be produced from the process itself, instead of being assembled afterwards. Four mechanisms make the difference.

The audit trail. Every important step leaves a trace: who submitted, who approved, which document was corrected, which attachment was replaced, which external operation was called and what came back. Every change of state records the previous state, the new one, who caused it and why. An action with several effects is correlated, so that it reads as one decision.

The versions. Every delivered file receives a cryptographic fingerprint — a SHA-256 hash computed from its bytes. If the content changes, the fingerprint changes. When a file is replaced because a reviewer asked for a correction, the fingerprint of the refused version is kept next to the one that replaced it, with who and when, so that it can be shown later that the content genuinely changed.

Approvals in sequence. Approvers decide in order, one at a time, and each decision is recorded with who, when, the position in the chain and the comment. When an approver rejects and the dossier is reopened, the chain starts again: an approval given against a version that no longer exists cannot go on standing. On the order and authority of approvers, we wrote a separate article.

The separation between suggestion and decision. When the AI extracts data and a person validates it in quality review, the decision is kept apart from the suggestion: the record says what the machine proposed and what the person confirmed, returned or rejected, with the reason and the scope of the correction. When a document is mandatory, that was recorded on the day the dossier was created. And a document's validity is a dated state, not somebody's note.

Where DOK Genius comes in

DOK Genius was designed so that document processes end with evidence, not merely with tidy files. Today, every dossier carries its history, every file its fingerprint, every approval chain its order and every quality review its decision. A cross-cutting audit centre shows correlated events and states how far back retention goes. The dossiers manual shows the history as it appears on screen; the approvals chapter explains the chain.

The next step is the evidence pack, on the roadmap: an auditable export of the dossier that turns its story into a shareable artefact — approved versions, approvals, file integrity and the sequence of events — to hand to an auditor, a customer or a regulator. The public roadmap says what arrives when.

For regulated teams, this reduces the effort of answering audits and increases confidence in decisions already taken. The features page describes the rest of the product, and the security page explains how isolation, permissions and audit records combine.

FAQ

Does a file's fingerprint prove who wrote it?

No. It proves the bytes have not changed since it was computed. It says nothing about authorship: that is the role of an electronic signature, a different instrument.

What happens to the previous version when a file is replaced?

The history records the replacement, by whom and when. When it answers a correction request, the fingerprint of the refused version is kept next to the new one, enough to show that the content changed and which version was accepted. The dossier keeps the current file; it is not an archive of every previous version.

Is the evidence pack available today?

Not yet: it is on the roadmap. Today, the history, the fingerprints, the approvals and the audit centre already exist and can be consulted in the product, dossier by dossier.

All articles

Get started

See it on your own documents

Open a free account, or tell us what your files look like today.