What good looks like
A documented timeline of the affected record, user, values, related actions, and required correction or escalation.
Have these details ready
- The record type and identifier
- Approximate date/time and expected value
- Authorization to view the affected business data
Run the workflow
-
Define the question
State the exact fact being investigated: what changed, expected value, time window, financial/operational impact, and known users.
-
Filter the history
Use entity type, record ID, user, action, and date filters to narrow results without exporting unrelated customer or employee data.
-
Read the sequence
Review creation, edits, approvals, status changes, integration events, deletions/recovery, and related workflow actions in chronological order.
-
Corroborate the record
Compare current state with quote versions, invoice/payment entries, messages, attachments, sync logs, or approval history. Distinguish user action from automation.
-
Correct through normal controls
If a business value is wrong, update it through the owning workflow with reason and approval. Do not alter audit evidence.
-
Document the outcome
Record findings, impact, correction, owner, and any permission, training, integration, or policy follow-up.
Check your work
Do not call the workflow complete until these statements are true.
- The exact record and time sequence are identified
- Evidence distinguishes user, workflow, and integration actions
- Correction and prevention actions are assigned
If something does not look right
No event appears
Expand the time window, verify record ID/entity and timezone, then check the owning record's local history or integration logs.
The change may be unauthorized
Preserve evidence, limit additional access only through approved authority, and follow the company's security/HR escalation process.