Administration
Governance: audit log, retention and erasure
Read and export the audit log, check signed deletion receipts, and complete or decline erasure requests with a signed certificate.
Governance is the evidence that tracking stays within what you disclosed: an audit log of every privileged action, signed receipts for every deletion, a privacy register, and the queue of erasure requests. It’s what a works council, data protection officer or auditor will ask to see.
The audit log#
Open WorkspaceGovernanceAudit log. Every edit, deletion, approval, live view, webcam request, screenshot deletion, policy change, export and sign-in setting change is recorded with who did it, when, the reason if one was given, and the exact before and after values. The log can’t be edited or deleted.
Filter
Narrow the log by target (for example Policy or Time entry), by Any actor — the person who did it — and by date range.
Open an event
Click a row to see the full event: the action, actor, reason, and a field-by-field before and after table.
Export it
Choose Export CSV to download the filtered log (up to 50,000 rows). The export itself is recorded in the log.
| Action | Actor | What it records |
|---|---|---|
| screenshot.deleted | Meera Nair (member) | A member removed one of their own screenshots — managers see “Removed by employee” |
| export.approved_hours | Priya Sharma (owner) | Who exported approved hours, the layout and the date range |
| project.archived | Priya Sharma (owner) | A project was archived, with the project before and after |
| privacy.erasure_requested | Meera Nair (member) | An erasure request, with the person’s note |
Retention and deletion receipts#
A retention job runs every hour. It permanently deletes screenshots and webcam images older than the workspace’s media retention — or the shorter Media retention override of the policy that applies to that device — and detailed activity (apps, sites, input counts, idle periods) older than the activity retention. Time entries and notes are never deleted by retention.
Every run that deletes something issues a signed deletion receipt. Open WorkspaceGovernanceDeletion receipts to see when each was issued, its kind and scope, the reason, how many items were removed and the signature, which you can copy to verify it independently.
| Setting | What it means |
|---|---|
| Workspace retention | WorkspaceSettings → Retention: separate day counts for screenshots & webcam and for apps, sites & input counts. |
| Policy override | Offline & retention → Media retention override in a policy. It can only shorten media retention for the people it covers. |
| Compliance limits | GDPR-safe keeps media for 90 days at most; HIPAA-safe keeps no media at all. |
The privacy register#
The Privacy register tab summarises what a works council or DPO typically asks for, backed by the live configuration: disclosure acknowledgements tied to the exact policy version, data exports served to members, erasure requests, deletion receipts, live-view and webcam sessions with actor, target, duration and reason, and the policy history.
Erasure requests#
Anyone can ask for their personal data to be erased from their privacy page. Requests appear under WorkspaceGovernanceErasure requests with the person, status, their note and when they asked.
| Person | Status | Their note |
|---|---|---|
| Meera Nair | Received | I am leaving Acme at the end of the month. Please erase my personal data. |
Complete a request#
Check who is asking
Confirm the request is genuine through your usual process, for example with HR.
Choose Erase
The dialog lists what will be Deleted and what is Kept, with the reason on the certificate. Optionally add a Note for the certificate, such as Identity verified by HR.
Confirm
Type ERASE and choose Erase data. This can’t be undone.
| What happens | What it means |
|---|---|
| Deleted | Screenshots and webcam images, live-view frames, apps and sites, input counts, idle blocks, time entries outside approved timesheets, notifications, sign-in methods and exports. |
| Anonymised | Name, email and device names are replaced, and the account is closed and signed out everywhere. |
| Kept, with the reason | Approved and locked timesheets (the payroll or billing record), the audit log, and consent records — attached to the anonymised person. |
TimeLogger then issues a signed erasure certificate listing exactly what was deleted and what was kept and why. Choose Certificate on the request to view it or Download certificate. A copy is emailed to the person’s address from before anonymisation.
Decline a request#
Choose Decline, give a Reason (tick This is a legal hold if it is one), and choose Decline request. Nothing is deleted; the person sees your reason, and the decision is in the audit log.
Safeguards
Questions#
Can anyone delete or edit audit events?
Why are approved timesheets kept after an erasure?
How can an auditor check a deletion receipt?
Something unclear or out of date? Tell your workspace admin, or write to the TimeLogger team from Settings — we update these guides with every release.