Back to all guidesGovernance · 9 min read · Updated 26 July 2026

Approval history: what a useful audit trail should record

Learn which versions, people, decisions, comments, dates, and access events belong in a creative approval history.

Written by the Aproova product team from the review flows we build and test in the application.

Approval history: what a useful audit trail should record

“The client approved it” is not enough when a question returns months later. The record should show who decided, which version they saw, when they acted, and whether important comments were still open.

An audit trail helps the team reconstruct the workflow. It does not turn every click into a contract or replace requirements that apply to a regulated process.

Tie every action to a version

The review, file, version number, and upload time form the start of the record. In a multi-file package, approval of one asset should not look like approval of every asset.

Comments, resolved items, and decisions are different actions. Closing a comment confirms it was handled; it does not approve the version.

Record people, decisions, and useful access events

Keep the name or email associated with the decision, the outcome, and the timestamp. External identity can be entered by the reviewer or limited to invited email addresses, depending on the review setting.

Public-link events help explain participation. They are operational evidence and should be read together with the approval rules agreed by the parties.

Use certificates and retention with clear limits

After the current version is approved, Aproova can generate a PDF summary of certified files, versions, comments, decisions, signatures when used, and recorded public-link events.

The PDF reflects the records available when it is generated. Retention varies by plan, and legal or regulatory validity still depends on the relevant agreement and requirements.

What an approval certificate cannot prove on its own

A certificate summarizes the records stored by the platform. It does not determine whether a participant had legal authority to bind a company or whether a regulated document met every external requirement.

Define the approval rule with the client or internal team first. The certificate then supports that process with a consistent operational record.

Questions people ask before setting up the workflow

Can Aproova generate a certificate before approval?

No. The current version must be approved and have at least one certifiable decision.

Do resolved comments disappear?

No. Resolution marks the item as handled while keeping it in the review history.

Is history retained for the same period on every plan?

No. Activity-history retention varies by plan and should be checked against the team’s internal policy.