The audit ledger nobody, including Kav, can edit
Every staff look at a resident's personal data is a permanent, purpose-carrying record — and the ledger itself refuses edits.
"Who looked at my file, and why?" is a question a resident is entitled to ask about any system handling their personal data — and one a lot of systems can't actually answer with certainty, because the log that would answer it can itself be edited or deleted after the fact.
What gets recorded
Every staff view of a resident's personal data — and every refused attempt to view it — is written as a record naming the actor and the purpose. This isn't a general application log line; it's a specific, structured audit record, generated at the same disclosure boundary that decides whether the view is even allowed.
Why "nobody can edit" is the actual guarantee
The ledger itself refuses updates and deletes, enforced at the database level rather than left to application discipline — which is what makes it a real answer to "who looked, and why," rather than a log that's only as trustworthy as everyone who could have touched it afterward.
The same boundary that redacts also logs
This ledger isn't a bolt-on: it sits at the identical single disclosure boundary that redacts personal data by sensitivity class before it ever leaves the platform. A staff member seeing less than the full record, and that staff member's view being logged, are two outputs of the same checkpoint — not two separately maintained systems that could drift apart.
What this means in practice
A municipality or a business running this platform can answer, precisely, every time a member of staff saw a specific resident's or customer's personal data, and why — because the platform cannot represent that view without also recording it.