BE Teck Notes Back to be-teck.com

5 min read

The paper trail a query demands

Years later somebody asks you to substantiate a decision. What survives is a dated record, a named author, an unedited document and proof it was sent.

A query arrives long after the work. An authority asks why a particular payment was released. A lender's diligence team asks who approved a change in scope. Your auditor asks which version of a drawing the slab was cast to. A buyer's advocate asks what your side committed to, and when. A tribunal asks what you knew on a date.

None of them is asking to see your system. Nobody has ever asked a builder to demonstrate software.

The question is always narrower and always the same shape: show me the decision, and who made it, on the date you say it was made. That is a smaller thing than the pile of paper most offices keep, and most offices still cannot produce it.

The four parts of an answer that holds#

A defensible answer has four parts, and it is only as strong as the weakest of them.

  • A record made at the time. Not a note written afterwards describing what happened. A record whose own date sits inside the period it describes.
  • An identified person. A name attached to the act of deciding, not to the act of typing. "Approved" with no author is a fact with nobody standing behind it.
  • The thing decided about. The drawing, the rate, the bill, the variation — in the version that was in front of the person at the moment they decided.
  • Evidence it was communicated. A decision nobody was told about is indistinguishable, later, from a decision that was never made.

Three out of four is not a partial answer. A dated approval by a named person against a document you can no longer identify is worth very little, and you will spend the meeting explaining why.

The four things that destroy a defence#

Every construction office has at least two of these.

A spreadsheet with no history. It shows today's figures. It cannot show what it said on the date in question, who changed a cell, or whether a cell was changed at all. The other side does not have to prove it was altered. They only have to observe that it could have been, and the file stops being evidence and becomes an assertion. That is the argument for records that are added to and never overwritten.

A message on a phone that no longer exists. The approval was given on WhatsApp. The handset was replaced, the chat was not backed up, the person has left. Or the chat survives and shows haan, kar do with no reference to which of the three pending items it answers. A message is a real communication and a poor record: no structure, and it lives on hardware you do not control.

A document that exists in three versions. Revision A on the site engineer's laptop, revision B in the contractor's mail, revision C printed and signed in a file nobody can find. Nothing marks which one was signed. Every version is plausible and none is authoritative, so the version produced by whoever is better organised becomes the truth.

A signature nobody can attribute. A scanned initial on the last page. It could have been placed by anyone with access to the scanner, and the page under it could have been swapped. The live question is not whether the mark is genuine but whether the document beneath it is the one that was signed, and what makes a document tamper-evident is a different discipline from collecting signatures.

Why reconstruction is worse than a gap#

When the query lands, the instinct is to make the file complete. Somebody drafts the missing minute, dates it back, gets it signed, and puts it where it should have been all along.

This converts an administrative weakness into a credibility problem, and those are not the same size.

A gap is ordinary. Records go missing, people leave, a period was chaotic. Every experienced reviewer has seen it and has a way of dealing with it.

A document contradicted by its own metadata, or by another file that survived, or by a person's memory under questioning, does something worse. It puts every other document you produce into doubt. You are no longer defending one decision. You are defending your records as a class, and you will lose that argument even where you were right on the merits.

Say the gap exists. Say what you do have around it — the payment that went out, the material that arrived, the mail that referred to the meeting. A consistent partial record supports an inference in your favour. A perfect record that appeared afterwards invites the opposite one.

What a trail costs its own keeper#

Our own audit trail is a hash chain. Each entry is bound to the one before it, so a row cannot be inserted afterwards without the verification failing.

That has a consequence we did not plan and have come to like. When we repair data by hand — a correction we authorised, for a reason we would defend — we cannot also write ourselves a tidy audit row explaining it. There is nowhere to put one that would not break the chain. So the repair is written up in a dated change log that people read, in words, instead.

A trail nobody can quietly add to is a trail that makes its own keeper accountable. It costs a little convenience, and that cost is the property.

The parts you can fix now#

You cannot build a paper trail for a query that has already arrived. You can build one for the queries that have not.

  • Fix the moment of capture. The record is made when the decision is made, by the person who made it — not summarised on Saturday by somebody else from memory.
  • Make authorship unavoidable. If a field can be filled without recording who filled it, sooner or later it will be.
  • Keep one authoritative copy. Not a canonical folder that people copy out of. A place where the version in force is the one you open.
  • Keep the sending, not only the sent thing. The date an instruction or a demand went out is more often the disputed fact than its contents.
  • Make money decisions attributable to two people. Above a threshold you set, two signatures on money answers "who authorised this" before anybody asks.

Where any of this touches a filing, a certificate, a registration or a limitation period, the structure is general but the specifics are not, and they change. Verify the version in force with your own advisor rather than settling it from general reading.

The short version#

Nobody will ask to see your system. They will ask you to substantiate one decision, made by one person, on one date. That needs a record created at the time, a named author, the document as it then stood, and evidence it was sent.

The four things that destroy it are a historyless spreadsheet, a message on a replaced phone, a document with three versions, and a signature nobody can attribute. Building what an audit trail is for into the ordinary working day is what turns that query into a lookup instead of a scramble.

Have a gap worth closing?

If something in your daily work is broken in a way everybody has stopped complaining about, that is exactly what we want to hear.

Write to hello@be-teck.com

More notes