Updated Jul 2026
What the audit trail records, and why it holds up
Suppose a carrier asks about a post from last spring. What did it say, who cleared it, and was it reviewed before it went out? This page explains what PostSignoff can produce in answer, and why the record is built the way it is. For where to find all of this on screen, see Keep an audit trail of what went out.
What the record holds
For any published post, the durable record has several parts.
The published copy itself, exactly as it went out, text and images both. For older posts published before this was tracked, the record is rebuilt from the post’s current content and labeled reconstructed, so you always know which kind you’re looking at.
The AI’s original draft. When you edit a post, your edit is stored separately and the original is never overwritten, so the record shows both what the AI proposed and what a human turned it into.
The compliance review, if your brand has compliance review turned on. Each analysis is its own record, tied to the exact content, sign-off, and hashtags it checked. Edit the post and analyze again, and a new record is created alongside the old one. Nothing gets replaced. A post’s compliance history is a series of reviews, each permanently matched to the wording it was run against.
Any acknowledgement of findings, with who made it, when, and a fingerprint of the exact content it covered.
The approval, with who approved and when, for posts approved in-app. The approver appears as an internal account identifier rather than a name or email, and posts approved before this was tracked may show nothing here.
The record also keeps the content as it stood when the post was created, with its source and timestamp, and the post’s lineage, meaning the campaign or template it came from. One honest caveat: the version history records the moments a post was created or a platform version was added, not every edit in between. It tells you where the post started, not each keystroke since.
Why the published copy is locked
Once a post publishes, its text, sign-off, and hashtags can never be changed again. Not by you, not by anyone. There’s no override.
That sounds strict, and it is, deliberately. A record you can edit after the fact is a record you can’t rely on, because nobody reading it later can be sure it still says what it said on the day. The lock is what makes the published copy trustworthy as evidence. When you show someone what went out, you’re showing them something nobody could have quietly revised.
Nothing disappears
PostSignoff has no permanent delete for a post. Rejecting a post keeps it, with its content and its history, and it can be brought back later. Even archiving is a status change, not destruction.
This matters for the same reason the lock does. A supervision system that lets drafts vanish has holes in its story. If a reviewer turned something down, the record of that decision is part of how you show the process worked. The posts you declined say as much about your review as the posts you approved.
When you approve over a finding
Sometimes a compliance check flags wording you’ve decided to keep. When you acknowledge the finding and approve anyway, the record shows it: the review’s status and summary, an “Attested by … on …” line, and the acknowledgement text.
That’s a defensible position. The trail shows a human saw the finding, weighed it, and made a judgment call, on a specific date, against specific wording. A trail with no record of the finding is not. And because the acknowledgement is fingerprinted to the exact content that was analyzed, it can’t silently carry over to different text. Change the wording and a fresh analysis, and a fresh decision, are required. See Acknowledge findings and approve anyway for how that works in practice.
What the record is for
In practice, this record gets used three ways. Answering a carrier or regulator inquiry about a specific post. Internal review, when you want to look back at what was published and how it was handled. And demonstrating that a supervision process exists at all: content was drafted, reviewed, decided on by a named account, and published, in that order, with each step on record.
What the record doesn’t do is decide whether your process satisfies any particular regulator. That judgment stays with you. As the app’s own disclaimer puts it: “It assists supervision; it does not certify or guarantee regulatory compliance.” The record’s job is narrower and more useful: to make sure that when someone asks, you have something exact to show them.