Security & audit trail

A record is only worth keeping if nobody can quietly change it.

Vordr treats a signed inspection the way a bank treats a statement. What follows is how that is enforced, in plain terms.

Sealed at signature

When the venue contact signs, the record closes. No field can be edited afterwards, by anyone, including global admins. A correction is a new record that points at the original.

Event timeline

Arrival and distance from the venue, each retry, each custody change, the signature and the moment the office received it. Times are recorded on the device and reconciled on sync.

State derived from events

A device is Deployed, Faulty or Retired because of what happened to it, not because somebody set a field. The estate view is recomputed from events on every read.

Versioned templates

Every record names the template version it was answered against. Published questions cannot change key or type, so a report over twelve months compares like with like.

Roles and capabilities

Technicians see their own surveys and nothing else. Admin actions are gated by capability, not by page. Invitations expire and cannot be reused.

The PDF is the record

The signed PDF carries the record id, the seal time, signer and witness. Anyone holding it can be shown the same record in Vordr.

A timeline, as recorded

Plain sentences, exact times.

This is the right-hand column of every inspection record.

14:03Aakash Patel opened the job 40 m from Harbourside Tavern.
14:11Scanned label VF-88120311; bound to EFTPOS 1 of 2.
15:27Receipt printer test page answered Fail. Action raised.
16:42Signed by R. Nguyen (venue manager). Record sealed.
16:43Received by the office. rec_01J7Q…
Security · Vordr