What should an EWA audit trail record?
The audit trail must reconstruct each decision and cash movement end to end.
More than a history of time edits
Record the chain across profile, workplace, work, approval, rate, policy, calculation, eligibility, account, transaction, bank, reconciliation and payroll.
Worker-profile audit trail
Retain creation, identity changes, employment status, workplace links, timekeeping IDs, receiving account and controlled device changes, with actor, time, before/after, reason and source.
Work and approval audit trail
Bind approvals to a data version and record source, original value, approver, time, edits, actor, reason, reapproval and affected transactions.
Policy and configuration audit trail
Store policy ID, version, effective date, client scope, relevant values, creator, approver, activation and retirement; every decision keeps the version used.
Earned Wage Engine audit trail
For financial decisions preserve approved work, rate, period, withdrawals, reserve, source, snapshot time and result so the calculation can be reproduced.
Eligibility Engine audit trail
Record worker, assessment time, input amount, policy version, key rules, outcome and reason code such as eligible, insufficient work, verification incomplete, client disabled or pending transaction.
Transaction audit trail
Keep transaction ID, request ID, idempotency key, worker, masked account, amount, timestamps, every state, bank response, reference, retries, manual intervention and final result.
Pending and retry audit trail
For timeout, record send time, missing response, pending transition, investigation, retry decision, identifiers and evidence supporting final status.
Reconciliation audit trail
Record comparison source, file/snapshot, date, matching key, matches, differences, exception code, owner, action and closure evidence—not only a boolean.
Payroll-posting audit trail
Trace period membership, successful/failed/pending handling, received total, posted payroll amount, approver, bridge report and differences so each amount is deducted once.
Event log or only updated_at?
updated_at cannot show actor, changed field, before/after, reason or affected decision; important events need a dedicated audit log.
Minimum fields in an audit event
An event needs ID, entity type/ID, actor, action, time, before, after, reason code, correlation ID, source and approval.
| Field | Meaning |
|---|---|
| Event ID | Event identifier |
| Entity type | Work, policy, transaction, payroll |
| Entity ID | Related record |
| Actor | Person or system |
| Action | Create, edit, approve, send, reconcile |
| Timestamp | Time |
| Before | Previous value |
| After | New value |
| Reason code | Reason |
| Correlation ID | Event-chain link |
| Source | App/API/Sheet/ERP/bank |
| Approval | Approver if required |
How should logs resist alteration?
Ordinary users cannot delete logs; reading is role-based; log changes leave traces; clocks align; protected information is masked; retention follows policy.
Audit does not mean retaining everything forever
Keep enough to prove and operate, but avoid copying full IDs, bank accounts, location, face images or irrelevant personal data; prefer references, masks or hashes.
Who needs access to the audit trail?
Workers see relevant status, client managers scoped work, payroll offsets, operations transactions, engineers necessary system logs, and audit/legal authorized records; sensitive-log access is itself logged.
How does it resolve complaints?
A timeline can explain which work changed, who edited and reapproved it, the policy version, successful transaction, changed withdrawal total and new calculation.
Audit-quality KPIs
Measure events with actors/reasons, end-to-end traceability, missing correlation IDs, unapproved manual edits, exceptions without closure evidence, investigation time and unreproducible complaints.
Conclusion
A good audit trail reconstructs one decision and one cash flow from origin to payroll, making EWA explainable, controllable and faster to correct.
Author: Do Huy Le — General Director, Nhan Kiet Manpower Supply Co., Ltd.
EWA: Hotline 0937.022.655 · Email info@nhankiet.vn · EWA
FAQ
Is audit only for auditors?
No, it supports operations, support, incidents, reconciliation and complaints.
Must every app opening be logged?
Not necessarily; prioritize events affecting data, rights, decisions and money.
How is this different from article 135?
Article 135 focuses on before/after time edits; this article covers the full EWA chain.
Should full protected information be stored in logs?
No by default; apply data minimization and role-based access.