Keep every workforce-record change connected to its evidence.
One record, every material change — source event, deterministic classification, worker correction, authorized review, approval, release, acknowledgment, and reconciliation, connected and attributable from end to end.
Record REC-88214-A
v4 · ApprovedSource status
Verified
Policy / version
Break & Rest v3.2
Current use
Payroll reference
Source event captured
Aug 4, 2026 · 07:02 PDT
Classified against policy v3.2
Aug 4, 2026 · 07:02 PDT
Correction submitted by worker
Aug 5, 2026 · 09:14 PDT
Approved by reviewer
Aug 6, 2026 · 14:40 PDT
Release & receipt pending
Awaiting downstream acknowledgment
Material history, not a raw telemetry feed.
An activity log records everything that happened. The Evidence Ledger records what changed, why, and what it connects to — and says plainly what it can't show.
Raw activity log
- Every raw signal, regardless of materiality
- Flat, chronological, disconnected entries
- No linkage to evidence or policy context
- Corrections often overwrite silently
Evidence Ledger
- Material lifecycle transitions only
- Object linkage across record, version, evidence, decision
- Evidence context and availability shown explicitly
- Corrections create linked history, never overwrite
Persistent limitation
The ledger explains what changed and why it's connected — it is not a completeness guarantee, a legal-admissibility claim, or proof of correctness. This applies everywhere in the product, not just here.
One record, eight connected stages.
Late events, conflicts, and withdrawn evidence are shown as part of the record — not smoothed into a falsely clean timeline.
Source
Material event
Clock-in captured
Actor
Time capture service
Validate & Contextualize
Material event
Location & device confirmed
State
Contextualized
Classify
Material event
Matched to policy v3.2
Next action
Await review if flagged
Review & Correct
Material event
Worker correction submitted
Owner
Assigned reviewer
Approve & Resolve
Material event
Reviewer decision recorded
State
Approved · v4
Release
Material event
Sent to downstream system
State
Queued for delivery
Acknowledge & Reconcile
Material event
Destination receipt matched
Next action
Resolve if mismatched
Retain / Restrict / Redact / Archive
Material event
Retention policy applied
Owner
Privacy & lifecycle admin
Every material event, fully explained.
No event is a bare line item — each one expands into identity, timing, reason, evidence, and what happens next.
EVT-30456 · type: correction_approved · v4
Resulting state: ApprovedAffected object
REC-88214-A
Actor / service
J. Alvarez — Compliance Reviewer
Role / scope
Reviewer · Team 12 scope
Canonical timestamp
2026-08-06T14:40:11Z
Local timestamp
Aug 6, 2026 · 7:40 AM PDT (UTC-7)
Action / reason
Approved worker correction — break duration
Before → after
25 min → 30 min
Source / policy context
Break & Rest Policy v3.2
Evidence references
2 available, 1 restricted
Relationships
Supersedes EVT-30401
Retention state
Standard retention · not restricted
Owner / recovery
Compliance Reviewer team
Version comparison, not silent overwrite.
Every correction, reclassification, or reopening creates a new linked version — the prior version stays visible, not deleted.
v1
Source
v2
Normalized
v3
Corrected
v4
Approved
Comparing v3 (Corrected) against v4 (Approved). Select a version above to change the comparison.
Your record, explained in plain language.
Workers see their own history, why something changed, who acted, and how to request a correction — not a black box.
Worker rights, always
- Full access to your own record history
- The right to request a correction
- The right to escalate an unresolved request
- Never required to waive correction, privacy, appeal, grievance, legal, or contractual rights — under any tier or configuration
The ledger records context. It does not decide.
Accountable people make the call — the system's job is to make sure they have what they need to make it well.
Approval, correction outcomes, payroll effects, discipline, legal conclusions, and other external decisions are kept separate from ledger state. The ledger shows that a decision was made, by whom, and why — those decisions themselves belong to authorized people and processes outside the ledger.
Ten explicit states. No universal "complete."
Each state carries text and an icon — never color alone — and a clear recovery path. There's no completeness percentage here; evidence availability is stated per item, not summarized into a score.
Accessible to authorized viewers now.
Exists, access is scoped by role or purpose.
Expected but was never captured.
Available, but past its expected refresh.
Removed by an authorized source action.
Replaced by a newer linked version.
Present, with content masked by policy.
Cannot currently be retrieved or shown.
Multiple sources disagree — flagged for review.
State could not be determined.
A governance layer, not an open shelf.
Access is scoped by role and purpose — nothing here implies every administrator sees every event.
Role & purpose-based access
Every view is scoped to a role and a stated purpose — not open by default.
Field-level masking
Sensitive fields can be masked independently of whether the record itself is visible.
Attributable redaction
A redaction is itself a logged, attributable action — not an invisible edit.
Policy-controlled retention
Retention follows configured policy, not a single universal duration across every org.
Preservation & restriction
Records can be held or restricted, without implying automatic legal-hold coverage.
Access review
Who accessed what, and why, is itself reviewable — access isn't a one-time grant and forget.
Export is a controlled workflow, not a download button.
Every package states its purpose and limitations up front — it is never presented as an unrestricted log dump or a legal-proof package.
Define Purpose
Select Content
Apply Access / Redaction
Review Limitations
Approve
Generate Package
Deliver
Record History
See the product, not a mockup of a promise.
Synthetic organizations, IDs, and evidence throughout — no real names, photos, or confidential content.
1,204
Records with material events this week
18
Open review items
96%
Evidence available (this org, this period)
3
Reconciliation items needing review
Overview shell: left navigation (Records, Events, Evidence, Review & Corrections, Exports, Reconciliation) with scope and date controls at top. Counts and results are server-authorized per viewer.
What the Evidence Ledger is not.
The Evidence Ledger is never presented as:
- Blockchain-based or immutable
- Tamper-proof
- Legally admissible evidence
- Regulator-ready or statutory audit evidence
- Universally complete
- A guarantee of correctness or compliance
- A surveillance dashboard or raw telemetry store
- An employee-monitoring timeline
It also does not make consequential decisions.
Payroll outcomes, discipline, misconduct findings, legal status, and other external decisions remain with authorized people and processes — the ledger provides context for those decisions, not the decisions themselves.
Evaluate it the way your team actually evaluates software.
Real product UI, a Trust Center, and a demo with your questions — not a fear-based compliance pitch.
Record scope & identity
What's captured, from which sources, tied to which identity and access model.
Evidence lifecycle
How evidence moves from capture through availability states to retention or redaction.
Change integrity
How corrections, reclassification, and reopening create linked history.
Exports & integrations
How governed packages are built, delivered, and reconciled downstream.
Worker rights
How correction, escalation, and access work from the worker's side.
Privacy & legal governance
How access, redaction, and retention are configured and reviewed.
Traceable history. Accountable review. Worker rights, intact.
Start free and connect your first record, or bring your enterprise evaluation questions to a live demo.