Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Recording Who Did What
Python & Django

Recording Who Did What

Django audit trails that record who changed what, when and from what, on the models that matter, stored immutably and queryable per record.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Record who changed what, when and from what to what, on the models that matter. Store it immutably and make it queryable per record.

Reconstruction is the standard

The question is rarely “what is the current state?” It is “how did this record get into this state, and who decided?” That requires history recorded at the time.

History cannot be reconstructed after the fact. Either it was recorded when the change happened or the answer does not exist.

What to record

  1. Who — the authenticated user, or the system process
  2. When — with a time zone
  3. What changed — field, old value, new value
  4. Why, where a reason is required by the process
  5. From where — the web interface, an import, an API

Not everything needs it

AuditDo not bother
Financial recordsSession data
Anything customer-facingCache entries
Permission changesSearch logs
Status transitionsDraft working data
Anything disputedEphemeral records

Auditing everything produces volume that makes finding the important entries harder. Audit what matters.

Make it immutable and queryable

  • Write-once — audit records that can be edited are not audit records
  • Queryable per record, so a specific history is retrievable quickly
  • Retained per your records policy
  • Visible to the people who need it, restricted from those who do not

Balance against data minimisation

Full audit history contains personal data, and retaining everything indefinitely conflicts with minimisation obligations.

Set a retention period aligned to your records policy and apply it automatically. Both requirements can be met; neither is met by accident.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Should we use an audit library?

Established options handle model change tracking well. Business-level events frequently need explicit recording alongside.

How long should audit data be kept?

As long as the underlying business record, typically. Align it to your existing policy.

Does it slow things down?

Marginally. Writing audit records on high-volume tables needs consideration; on ordinary business records it is negligible.

Who should see the audit trail?

Those who need it for their role. It contains information about colleagues' actions and should not be generally visible.

Keep reading

More on Python & Django

Python & Django

An API Other Systems Can Depend On

Designing a Python API service others can depend on: validation at the boundary, consistent errors and status codes, early versioning and documentation.

Python & Django

Moving and Transforming Data Reliably

Building data pipelines in Python that cope with malformed input: restartable stages, quarantining failures, reconciling counts and alerting on absence.

Start here

Cannot explain how a record reached its current state?

That is an audit gap. Adding history to the models that matter is a contained piece of work.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →