BookKeptevidence chain
Documentation

The evidence pack and the audit chain

The product is the join. Everything else in this system exists so that one question, asked about one placement, can be answered from one record instead of from four systems and somebody's memory.

The chain

Every compliance-relevant act writes an audit event: issuing a KID, approving a timesheet, recording a right-to-work check, filing umbrella evidence, generating an invoice, changing an umbrella's risk status. Each event carries a hash of the one before it.

Audit rows are never updated and never deleted. A trail that can be edited answers a different question from the one an inspector is asking.

Because the events are chained, a removed or altered row breaks the chain from that point on. The value of that is not cryptographic theatre: it is that the trail is either intact or visibly not, rather than quietly plausible.

The pack

An evidence pack assembles everything held about one placement: the placement itself, the worker and client, the umbrella and its evidence position, the right-to-work record, the Key Information Document, the assignment confirmation, the weeks and who approved them, and both invoice series. One call, one document.

This is the thing an agency currently builds by hand the night before an audit, out of a spreadsheet, a shared drive, an inbox and the accounting package. Assembling it in advance is not the same as holding it: what makes it defensible is that each piece was recorded when it happened, with its date, by a person the record names.

Retention is a deliberate act

Documents carry a retention category and a date. Deletion happens as a scheduled, logged act rather than as a delete buried in a service method, so both keeping something and destroying it are decisions the record can account for.

What an inspector actually asks

Not "do you have a policy". The question is closer to: this worker, on this assignment, in this week, show me the right to work, the key information document, the umbrella you paid through, the hours the client agreed and the invoice you raised. Every one of those is a different system in most agencies, and the join between them is the work.

See it working

One placement, the whole chain

Open the demo and build an evidence pack for any placement. It is the same call an API key makes.

Have it set up for you