Cityworks audit logs need configured scope and retention proof
Cityworks' PLL documentation says permits and cases are audited by user, date, time, and change, while also saying administrators can limit auditing to selected groups or items. A jurisdiction should verify the configured event population, identities, prior values, retention, exports, and custody before relying on the log as a complete public record.
Editorial figure by Civic Permit Review. Source context: Office and Tablet for PLL Overview.
Convert the audit claim into an event inventory
The official PLL overview pairs a broad audit statement with a material configuration boundary. It says the system tracks user, date, time, and changes, and it also says auditing can be limited to selected groups or items. Those statements can both be accurate. For a jurisdiction, the useful question is therefore not whether an audit feature exists, but which objects, fields, actions, interfaces, and administrative changes create an event in the deployed configuration.
Build an audit-scope matrix for applications, contacts, parcels, addresses, plans, reviews, comments, conditions, fees, payments, inspections, violations, hearings, notices, documents, issuance, renewals, closures, reopenings, integrations, permissions, and configuration. For each object and action, record whether create, view, edit, delete, status transition, assignment, approval, export, and override are logged; which fields carry old and new values; how actors are identified; and which source proves the current setting. Unknown coverage should remain visible.
Test identity, time, and change semantics
A user name, date, and changed value can still be ambiguous. Verify whether the actor is a named staff member, contractor, applicant, service account, integration, delegated session, or administrator; whether identity survives directory changes; and whether impersonation or shared accounts are prohibited and detectable. Record timestamp precision, time zone, clock source, ingestion time, effective time, and ordering rules so reviewers can reconstruct events that cross midnight, batch jobs, or system outages.
Test null-to-value, value-to-null, multi-value fields, document replacement, attachment deletion, bulk update, workflow reroute, reassignment, fee override, payment reversal, inspection correction, and reopened case. The log should show which record and version changed, the earlier and later values where material, actor, reason when required, source interface, and related approval. A final status alone cannot explain whether a valid decision path was followed or whether an integration overwrote staff work.
Prove retention and export before a records request
Search and spreadsheet export are useful capabilities, but a successful export is not evidence that the population is complete or retained for the required period. Define retention by event class and jurisdictional policy, including legal holds, archived cases, migrated records, deleted objects, former users, and configuration history. Preserve who can alter audit settings or purge data, how those administrative actions are logged, what backups contain, and how restoration affects event identifiers and chronology.
Run a bounded export for one permit or case and reconcile the row count and event types to the source log using stable identifiers and a documented cutoff. Test pagination, filters, time zones, formatted versus raw values, embedded line breaks, attachments, large histories, and events arriving during extraction. Hash or otherwise control the retained export where appropriate, record query parameters and custody, and keep later corrections separate. The spreadsheet is a derivative record unless the jurisdiction establishes otherwise.
Keep this decision separate from field connectivity
This Civic Permit Review analysis concerns the configured completeness, retention, and export of PLL permit and case audit evidence. It does not evaluate Cityworks Respond's field connectivity, offline continuity, or maintenance work-state protection; those are separate product, workflow, and publication boundaries. The PLL source establishes provider-documented audit and export capabilities, not a jurisdiction's records-law determination, configuration completeness, immutability, user accountability, or defensible response to a request.
Civic Permit Review reviewed the exact PLL documentation on September 3, 2026. No dated material development after the September 2 successful-run cutoff was established, so this is durable operating analysis rather than a current-intelligence event. The next priority is one witnessed case-history reconstruction from intake through review, fee, inspection, decision, notice, correction, archive, and controlled export, including a deliberate unlogged-field test and an administrator configuration change.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Civic Permit Review will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.