Policies Internal operating policies

Audit Logging Policy

What Map.ca logs for audit purposes, how those logs are protected, retained, and used.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 6 months
Master Policy Index entry
§4 #65

Policy text

Audit logs make appeals, incident review, and accountability possible. The Audit Logging Policy defines what events are logged (access, moderation actions, civic routing, AI-involved decisions, configuration changes), the log integrity posture (tamper-evident where possible), the retention period by log category, the access controls on logs, and the rules that prevent audit logs from becoming surveillance datasets.

It applies to engineering, security, moderation, and compliance functions.

Principles this policy enforces

  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Log moderation actions, AI-involved decisions, access events, and configuration changes.
  • Protect log integrity with documented tamper-evident measures.

What it forbids

  • Do not use audit logs as a surveillance dataset.
  • Do not retain audit logs past the documented retention period.

How it applies

References