The access log
Who has opened what, by person — chained so it cannot be edited quietly, signed so you can keep the proof, and exportable.
The access screen is admin-only and answers one question: who has opened
what.
This is a Teams feature.
It is a list of people, not of events
A row is a person. Tap one and it opens onto what they did — which is the shape
the question takes on the morning somebody leaves and you need to know what they
had.
The chain
Above the list: how many entries there are, whether they still agree with
themselves, and the signed head of the chain.
Each entry is linked to the one before it, so an entry cannot be changed or
removed without every entry after it disagreeing. The screen checks that and
tells you the answer plainly — including when it cannot: a cabinet with no
signing key has a chain that verifies and nothing signed to hand anybody, and
both halves are said rather than one.
Taking the proof with you
Export the anchor gives you a real file with the whole signed head in it —
not a tick meaning "we checked". It is meant to be kept.
There is a full export of the entries themselves too, for whoever asks you for
one.
What is recorded
That a person opened a machine, when, and at what level. Not what they did once
they were in — that never comes through us, and there is nothing here to record
it from. What happened on the machine is in the machine's own
logs.
Somebody who has left
Their row stays, with what they had and when it ended. An audit that forgets
people when they go is empty on the one day it is needed.