Choose the symptom you can observe
Open the matching case. Check the existing state before changing a record or repeating an action.
A recent billing change has no matching activity event.
Check first
- Search the correct organization, date range, source, and event status rather than the current record alone.
- Compare the record's update time with the audit history's event time and timezone.
- Check whether the change was made through a workflow that records a different event type.
Next action
Record the missing-event gap with the current record identifier and update timestamp, then route it to the audit or activity owner. Do not invent an actor or backfill a cause from the current configuration alone.
Confirm the result
The incident contains a reproducible search scope, current record state, and either a located event or an explicitly unresolved audit gap.
An audit event has an actor but the action is hard to interpret.
Check first
- Read the event source, action label, outcome, and linked record together.
- Compare the event timestamp with the before and after values on the affected record.
- Check whether the actor represents a person, an approved process, or an imported source.
Next action
Describe the event using only its recorded action and state transition, then ask the owning team to explain an ambiguous label. Keep interpretation separate from the retained event facts.
Confirm the result
The trace note names the actor, source, recorded action, before or after evidence, and the owner for any unresolved interpretation.
An audit event links to an invoice or report that does not match.
Check first
- Compare the linked identifier, entity type, franchise, and period with the event scope.
- Check whether the link points to a related line, file, or parent record rather than the detail being reviewed.
- Open the linked record and compare its creation or update time with the event.
Next action
Keep the event and linked-record identifiers separate, then route a relationship mismatch to the owner of the activity data. Do not relabel a related record as the affected invoice or report.
Confirm the result
The trace note states whether the link is exact, related, or unresolved and preserves both identifiers for follow-up.
The activity history appears to skip a state transition.
Check first
- Search a wider time range and include adjacent sources or outcome filters.
- Compare the first and last visible states with the record's retained timestamps.
- Check whether a batch, retry, or system process collapsed several changes into one event.
Next action
Document the observed before and after states and the missing interval, then route the gap for audit review. Do not fill the interval with an assumed successful action or use a later configuration as proof of what happened earlier.
Confirm the result
The final trace includes the search scope, visible state transitions, missing interval, and a named owner for any reconstruction.
Prepare a useful escalation
- Include organization scope, event source, time range and timezone, actor, action, outcome, and linked record identifiers.
- Keep raw provider or private payloads out of the operational note; retain only the permitted event facts and references.
- Ask the audit owner to decide whether a gap needs a system investigation or a business follow-up.
Reference the relevant record instead of copying credentials or unrelated personal information into the handoff.