Every litigator has spent an evening building a chronology from an email folder. Every compliance officer has been asked "when did we know?" and answered from memory. The chronology exists because the record did not keep one; the memory is relied on because the system had none.
Two records, kept automatically
The case timeline is the human-readable history of a matter: status changes, fields edited, files added, emails filed, comments, tasks completed, shares granted, documents generated — each with who and when. It is what you scroll to see how a matter unfolded.
The audit log is the system record beneath it: every action, every actor, every target, with timestamps written by the server. It covers things the timeline does not show — sign-ins, permission changes, exports, deletions, failed second-factor attempts. Members cannot edit it. Organisation owners and superadmins can read it; the deletion oversight and disclosure logs sit alongside.
What makes them usable as evidence
- They are contemporaneous. Written at the time of the act, not reconstructed.
- They are not editable by the people they describe. A record a party can amend is a record a party can be accused of amending.
- They are complete for the case. The timeline is per matter; there is no "other folder" where the rest of the history lives.
- Timestamps are the server's, not a workstation's clock.
Emails with their headers
An email filed into a case from Mail keeps its original headers: sender, recipients, Message-ID, the sending and receiving timestamps. That is the difference between "we have a copy of the email" and "we have the email". Forwarded copies do not have it.
Exporting the bundle
The timeline exports as a chronology; the files list with upload dates as an index; the contact roles as a cast list. Combine with the generated documents and the signed e-sign outputs (each with its own audit certificate) and the bundle is assembled from records rather than written from recollection.
Privilege and secured cases
Matters under privilege belong in Advanced-Security cases: encrypted with their own key, invisible to non-members, absent from the assistant and from the wider search. The audit log still records that the case exists and who touched it — which is what you need — without exposing what is inside.