# What is recorded When somebody asks you to prove that a document was reviewed and approved, a green tick is not an answer. Capable keeps a permanent record of every approval action on every page, tied to the exact version of the page it applied to. --- ## What is kept Every one of these is recorded with the person who did it and the time they did it. | **Event** | **Recorded when** | | --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Requested** | An approval is raised on the page. | | **Added** | Somebody is added to the approver list. | | **Approved, Rejected, Commented** | Somebody answers.[\[1\]](#fn-1) | | **Removed** | The approval is withdrawn. | | **Expired** | An approved page comes back around for review. | | **Published** | Approval triggers a publish. See [Publishing](https://help.gocapable.com/approval/publishing.html). | Each event carries the page **version** it applied to, so you can always answer which version of this document they actually approved. --- ## The history is append only Answers can be changed, but nothing is ever erased. If somebody approves, then changes their mind and rejects, both events stay in the record with their timestamps. ℹ️ The current status is a calculated value. The history is the evidence. See [View approval history](https://help.gocapable.com/approval/view-approval-history.html). --- ## Signed responses Where a space requires an authenticator code, responses given with one are marked as authenticated and shown with a padlock. No device or network detail is kept, only that a code was checked. See [Sign approvals with a code](https://help.gocapable.com/approval/sign-approvals-with-a-code.html). --- ## Capable checks its own records The approval summary stored on each page carries a fingerprint of its own contents, and Capable verifies it every time the status is displayed.[\[2\]](#fn-2) If the stored state no longer matches its fingerprint, or the approval no longer matches the version of the page it was given for, you are told, rather than being shown a status that is not true. | **Badge** | **Meaning** | | ------------- | ------------------------------------------------------------------------------------------ | | APPROVED | The record is intact and matches this version of the page. | | IN REVIEW | Also shown briefly after an edit, while things settle. | | CORRUPT | An approved page no longer matches the record. Investigate before relying on it. | | REPAIR NEEDED | Usually an approval old enough to predate this checking. Repair it to bring it up to date. | --- ## Getting the evidence out | **You need** | **Use** | | --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | One page, in full | The approval history on the page. See [View approval history](https://help.gocapable.com/approval/view-approval-history.html). | | A whole space or site, as a spreadsheet | An export from [Search and reporting](https://help.gocapable.com/approval/search-and-reporting.html), with the email columns added. | | Evidence inside the document itself | The approval macro in History or Metadata view, which travels into published sites. See [The approval macro](https://help.gocapable.com/approval/the-approval-macro.html). | --- ## What is not in this record Worth knowing before an audit, so nothing is a surprise on the day. * **Administrative changes are not logged here.** Turning the code requirement on or off, changing space settings, resetting an authenticator and editing team membership leave no trace in the approval history. * **The CSV export does not carry the signed marker.** The padlock is visible in Confluence but not in the exported file. * No device or network detail is kept against a signed response, only that a code was checked. * An approver can change their answer after completion. Both events are kept, but freezing a decision has to be a procedural control. See [Compliance](https://help.gocapable.com/approval/compliance.html). --- 1. The note left with an answer is capped at 500 characters. A long rationale belongs on the page itself, where it is versioned and searchable, rather than in the response box. [↩](#fn-ref-1) 2. There is a short grace period after an edit, so a page you have just changed shows In review rather than a warning while the update settles. [↩](#fn-ref-2) --- ## Related [View approval historyReading the record on a page.](https://help.gocapable.com/approval/view-approval-history.html) [ComplianceHow this maps to SOC 2, ISO and Part 11.](https://help.gocapable.com/approval/compliance.html) [Sign approvals with a codeWhat the padlock proves.](https://help.gocapable.com/approval/sign-approvals-with-a-code.html) [Search and reportingExporting across many pages.](https://help.gocapable.com/approval/search-and-reporting.html) [The approval macroCarrying evidence into the document.](https://help.gocapable.com/approval/the-approval-macro.html) [Common questionsRepair needed, and what it does.](https://help.gocapable.com/approval/common-questions.html) --- _Everything an auditor asks for, already written down._