Audit logs are not accountability
A log proves that something happened. Accountability requires proving that what happened was right — and those are separated by almost everything that matters.
When a regulator, a board, or an aggrieved customer asks an organization to account for itself, the organization very often reaches for the same artifact: the audit log. Here is the record. Every action is timestamped, attributed, and ordered. Nothing has been deleted; nothing can be. The implication is that the log is the accountability — that producing a complete, tamper-evident trail of what the system did is the same as answering for what the system did. It is not. A log and an account are different objects, and confusing the two is one of the more expensive category errors an institution can make, because the confusion is invisible right up until the moment someone presses on it.
The distinction is simple to state. A log answers what happened: which event occurred, in what sequence, performed by whom, at what time. Accountability answers a harder question — was what happened defensible. And defensibility is not a property of the action in isolation. It is a relationship between the action and three other things: the evidence the decision rested on, the rules it was bound by, and whether, given those, the same inputs would produce the same result again. A log captures the action and almost never captures the rest. So the log can be perfect, exhaustive, cryptographically sealed, and still leave you completely unable to say whether any of the steps it so faithfully records were warranted.
A complete log of unjustified steps is still a complete log of unjustified steps
Picture the cleanest case the technology can offer: a system that records every step it takes in a tamper-proof ledger, each entry signed, the whole chain verifiable end to end. An auditor can confirm, beyond dispute, that the system retrieved this record, then evaluated that condition, then issued this denial, in exactly that order, and that nobody altered the trail afterward. This is a real achievement, and it answers real questions — questions of sequence, of attribution, of whether the history has been tampered with. Forensic reconstruction is what such a log is for, and it does it well.
Now ask the accountability question: was the denial correct? The log is silent. It tells you the system evaluated a condition; it does not tell you on what evidence, because the evidence-state at the moment of evaluation was never preserved — only the fact that an evaluation occurred. It tells you a rule fired; it does not tell you which version of which policy was active then, because the rule-state drifts and the log points at a name, not the text. The trail records that actions were taken. It does not record the justifications those actions would need in order to be defended, and a justification cannot be reconstructed after the fact from a list of actions any more than a verdict can be reconstructed from a transcript of which doors the jury walked through.
A log tells you the machine did exactly this. It is mute on the only question that matters: whether it should have.
This is the gap, and it is not a gap of completeness. You cannot close it by logging more. Logging finer-grained actions gives you a more detailed account of what happened; it does not begin to touch whether what happened was right, because the evidence the decision consulted and the rules it was bound by are not actions — they are the context that makes the actions evaluable, and a record built to capture actions structurally omits them. A log of a thousand steps and a log of a million steps are equally incapable of telling you whether step one was warranted. Resolution is not the missing ingredient. The missing ingredient is a different kind of record.
The appearance of rigor is not rigor
What makes the error durable is that logs are trusted for the very reasons they should be questioned. They are voluminous, technical, and tedious to read — and we have a deep cultural reflex that treats volume and tedium as proxies for rigor. A document nobody can comfortably read feels more authoritative than one anybody can, and a record that fills a thousand lines feels like it must have left nothing out. So the log gets waved through. Few people in the room have the appetite to walk it line by line, and the few who do are confirming sequence and integrity, not justification, because justification is not in there to confirm. The thoroughness is real. It is simply thoroughness about the wrong question, and its sheer heft is what lets it pass for an answer to the right one.
This is worth saying plainly because it cuts against the instinct of careful people: the more impressive the trail, the more important it is to ask what it actually establishes. A pristine, immutable, exhaustively detailed log establishes that a sequence of events occurred and was not altered. That is genuinely valuable and it is genuinely necessary. It is not, by itself, evidence that the events were defensible — and an organization that mistakes the one for the other has bought reassurance, not accountability, and at a premium.
From logging to receipts
None of this is an argument against logs. Logs are necessary. You cannot account for a decision whose history has been quietly rewritten, and integrity and ordering are real prerequisites for everything that follows. The argument is that logs are not sufficient, and that the remedy is not a bigger log but a different artifact — one built to answer the accountability question rather than the forensic-reconstruction question.
Call that artifact a receipt. The move from logging to receipts is the move from recording what happened to recording what happened, on what evidence, under what rules, and reproducibly so. A Decision Receipt carries inside itself the evidence the decision actually rested on, the rules as they stood at the instant of decision — frozen, in full, not named by reference — and enough state that the decision can be replayed: the same inputs fed back through the same process to see whether they still land where they landed. A log lets you reconstruct the sequence and trust that it was not tampered with. A receipt lets you re-derive the conclusion and check whether it follows. The first is a history. The second is a thing you can argue with, which is the only kind of record from which accountability can be built.
The practical test is short. Hand someone your audit trail and ask: can they tell, from this alone, not just that the system acted but whether the action was warranted — on what it knew, under the rules in force, and would it do so again? If the trail records actions but not the evidence-state and rule-state and replayability that make actions evaluable, you have a log. It is necessary, and you should keep it. But do not let anyone present it as an account. An account answers for the decision. A log only swears it occurred.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.