What is an Audit Trail?
An Audit Trail is the complete, chronological, tamper-protected record of security-relevant actions in a system. Every entry answers at least: who carried out which action on which target, when, from where, with what result, and, for critical changes, with what approval. Unlike technical logs, which mainly serve operations and often rotate out after a short time, the Audit Trail is built for evidential value: complete, kept permanently, and not alterable after the fact. That makes it the foundation of every kind of evidence, from internal audits to reviews under NIS2 or DORA.
Audit Trail in detail
A robust entry includes actor, action, target, timestamp, source (such as an IP address or session), result, and context such as a ticket or approval reference. What matters is that these entries are generated automatically by the system: a manually maintained change list is not an Audit Trail, because it has gaps and can be reshaped after the fact. Tamper protection matters just as much, for example by making sure that not even administrators can change or delete entries.
The industry term revisionssicher ("audit-proof") sums up these properties. For entries containing personal data, the GDPR also applies: purpose limitation, restricted access to the trail itself, and defined retention periods are all part of the concept, because the evidence store is itself a data object that needs protecting.
Why the Audit Trail matters in Zscaler operations
In Zscaler operations, several people, often including service providers, change policies that affect the whole company. Without an Audit Trail, it is hard to reconstruct after an incident which change came from whom and when, and whether it was approved; troubleshooting turns into an interrogation. With a clean trail, that question is answered in minutes, and even legitimate changes can always be explained to affected parties and auditors.
NIS2 and DORA turn this into a duty to provide evidence: both require controlled processes for security-relevant changes and proof of them; the details are set by national implementation and supervisory practice. The expensive route is reconstructing evidence from views, emails, and memory before every audit. The cheap route is an Audit Trail that keeps a record automatically as part of daily work and produces evidence as a by-product.
Common sources of error
- Confusing logs with an Audit Trail: operational logs rotate, are incomplete, and are not tamper-protected; they are no substitute for evidence.
- Gaps through side channels: changes made directly in a view outside the process never show up in the trail; every change path needs to be captured.
- Shared accounts: without attribution to a named person, every entry loses its evidential value.
- Retention left unresolved: without defined periods, the trail either conflicts with the GDPR or has already been deleted by the time an audit needs it.
Audit Trail in practice: what CentaurNexus contributes
CentaurNexus automatically logs every write action in Zscaler operations in an append-only Audit Trail: actor, action, target, time, and origin, with four-eyes approvals, request and decision included. SHA-256 hash chaining makes any later change to sealed sections detectable. The evidence is a by-product of everyday work and can be used in reviews under NIS2 or DORA; Policy Health Saga can add a PDF report on configuration health on request. If the trail grows to enterprise volume, Audit Export exports it asynchronously as CSV or JSON, for example to feed a SIEM or for internal audit. The platform runs in Germany, so the audit data stays in the EU. The guide below shows how operations without admin rights and evidence come together: Zscaler support without admin rights.
Related terms
Frequently asked questions about the Audit Trail
At minimum, actor, action, target, timestamp, origin (such as an IP address or session), and result for every security-relevant action; for critical changes, also the approval reference, meaning who requested it and who approved it. The entries must be generated automatically by the system and protected against later change, otherwise they lack evidential value.
Revisionssicher (audit-proof) means: complete, traceable in chronological order, protected against later change, and available for the required period. Not even administrators may be able to change or delete entries. A manually maintained list or a rotating operational log does not meet these requirements; what is needed is system-side, tamper-protected logging.
Both frameworks require controlled, demonstrable processes for security measures and changes; they do not prescribe in detail how the evidence must be produced technically, national implementation and supervisory practice govern that. In practice, an automatic Audit Trail is the most reliable way to achieve the required demonstrability permanently and without extra effort.
Operational logs serve troubleshooting, rotate out after a short time, and may be changed or filtered. An Audit Trail serves evidence: it is complete, built to last, attributable to named people, and tamper-protected. Logs answer the question of what the system is doing right now; the Audit Trail proves who decided and changed what.
There is no single fixed period; it follows from industry, regulation, and internal policy. What matters is setting and documenting the period deliberately: long enough for audits and incident follow-up, while still compatible with the GDPR. Anyone who defines no period risks both problems at once: missing evidence and unlawfully retained data.
- Directive (EU) 2022/2555 (NIS2), risk management and evidence obligations - eur-lex.europa.eu
- Regulation (EU) 2022/2554 (DORA), ICT risk management and incident documentation - eur-lex.europa.eu
- Regulation (EU) 2016/679 (GDPR), accountability principle under Art. 5(2) - eur-lex.europa.eu
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.
Legal notice: This article reflects our assessment following thorough research of the original sources. It does not replace legal advice. Please have a qualified lawyer check whether and how the legal position described applies to your company. As of: 19 July 2026.