An audit trail that writes itself.
Every grant, approval, expiry, and revoke is recorded in an append-only log, timestamped, immutable, and exportable as branded evidence whenever the questions come.
- GRANTBeverly Crusher → Figma · admin
- EXPIREContractor → Notion
- REVOKETasha Yar → AWS · admin
Driply’s access audit log is the byproduct of how access already flows. Every grant, approval, expiry, and revoke is written once to an append-only Event log, with the actor, the reason, the level, and a timestamp, and never silently edited.
When a SOC 2 review, an ISO 27001 control test, or a vendor security questionnaire lands, the evidence is already there: export it as branded PDF or CSV, scoped to the period and systems in question.
Append-only by design
The log can’t be quietly rewritten after the fact, which is exactly what an auditor wants to see. The trail reflects what actually happened, not what someone reassembled later.
Every actor on the record
Each event names who did it, the requester, the approving admin or tool owner, the reason, and the expiry. “Who approved this, and why?” is answerable months later, in seconds.
Export on demand
Generate branded PDF or CSV evidence straight from the live record for SOC 2, ISO 27001, and Vanta- or Drata-style reviews, instead of assembling it by hand at quarter-end.
Evidence by construction, not reconstruction
Because the record is written as decisions happen, not rebuilt from memory under deadline. It stays trustworthy. Tenant isolation and least-privilege are enforced at the data layer, so the evidence you hand over is sound by construction. Automatic expiries keep least-privilege current between audits, so a periodic review reads off an already-accurate record rather than becoming an investigation.
Driply records access decisions as the authoritative source of access evidence; it complements compliance-automation tools like Vanta and Drata rather than replacing them.
The result, Walk into the audit with the evidence already in hand.
Questions, answered.
- What is in Driply’s audit log?
- Every access event, request, approval, denial, direct grant, level change, expiry, and revoke, with the actor, reason, level, and timestamp. It’s append-only, so entries are never silently edited.
- Can I export evidence for an audit?
- Yes, branded PDF or CSV generated from the live log, scoped to the period and systems you need, for SOC 2, ISO 27001, and vendor security reviews.
- Does it work alongside Vanta or Drata?
- Yes. Driply is the authoritative source of access-decision evidence and complements compliance-automation platforms rather than replacing them.