A customer forwards you a screenshot on a Tuesday in May and asks where their money has got to. It is a reply from your own support address, sent at 16:42 on 3 March, promising a full refund of $186 on a greenhouse that turned up with a cracked panel, delivery included, and they can keep the panel into the bargain. Nobody on the desk remembers writing it. The only name the Sent folder records is support@.
What settles a thing like that in a minute or two, without asking round the office, is a help desk audit trail, the running record kept on each ticket of which person replied and who changed what afterwards, with the time beside it and the old value sat next to the new one. The permissions decide who gets to make those changes in the first place, which is the other half of the job. Plenty of small desks run for years with neither, mind you.
Why a shared password leaves you nothing to prove
Go back to that afternoon in March. Five people work the desk at the greenhouse company in this example, made up but not far off plenty of real ones, and all five know the password to support@ on Google Workspace, on account of it being one paid mailbox that everybody signs into. At 16:42 three of them were logged in. Hannah had it open on the office PC. Mo had it on his phone in the van, and the Saturday part-timer had it on a laptop at home, finishing off a pile of returns, and any one of the three could have gone and pressed send.
So you ask round the kitchen, after Hannah has dropped the screenshot into the team’s Slack with three question marks under it. Hannah thinks it might have been her, since she was on breakages that week, though she would never in a month of Sundays have offered the whole $186 and let them keep the panel as well. Mo thinks it might have been him. Nobody is lying to you, funnily enough. They simply cannot remember one email out of the forty or so that went out that day, and why would they.
The admin console in Google Workspace does keep a log of sign-ins, and an admin with a bit of patience can usually see which devices were on the mailbox that afternoon. A device will never tell you which of the five was holding it, all the same. Two people can sit at the one office PC an hour apart. And a phone that signed in back in January stays signed in until somebody goes and changes the password, which on a shared login nobody wants to do, on account of then having to tell four people the new one. One of them is usually on holiday.
Shared logins nearly always start with a price per person. A desk that pays per seat buys one seat, or two, and everybody else who answers the odd mail gets the password on a sticky note, the warehouse included. We went into what that sort of pricing quietly rations over at our page about help desk pricing models, so here it will do to say that the greenhouse desk had paid for one mailbox and had five people answering out of it.
Gmail delegation is a real step up from the sticky note, since each delegate goes in under their own account and the customer sees the delegate’s own address beside the mailbox name. A shared mailbox in Outlook on Microsoft 365 also has everybody opening it under their own login, though with the usual Send As set-up the reply goes out under the shared address alone. Either way there is at least a fighting chance of finding out who sent a thing, which is more than a password on a sticky note will ever give you. The Gmail side of it gets a page of its own from us before long.
What should the record on one ticket actually show
Most desks keep a record of some kind already. There is the Sent folder, and the thread its self, and on a well run desk a spreadsheet in Google Drive where refunds get written down at the end of each day. None of those hold the order things happened in with a name against each step, and that order is the bit you need when somebody asks how a decision got made, a customer usually, now and then your accountant.
Here is the greenhouse ticket the way a proper trail would have kept it. The customer’s mail came in at 09:12 on 3 March with the Shopify order number in the subject, and a rule tagged it as a breakage. Hannah picked it up at 09:40 and moved the priority from Normal to High. Both of those sit in the trail with her name and the time on them, Normal still showing as what it used to be. At 11:05 Leon in the warehouse added an internal note saying panel four was cracked and there were six spares on the shelf, which the customer never saw. The refund reply went at 16:42 from Mo’s login, though nobody had gone and touched Stripe yet. At 16:44 the status moved to pending, Mo again.
Read in that order the thing explains its self. Mo had the ticket open late in the day, he never scrolled up as far as Leon’s note, and he went and offered the refund the policy does not allow, in good faith, at the tail end of a long afternoon. Nobody needs a telling off for any of it. What you have instead is a short chat with Mo about the note he missed and a decision on the $186, made in ten minutes with the whole of it in front of you.
The note at 11:05 did more of the work than the reply did, truth be told. A trail that kept replies only would have left it out. You would know who sent the refund and never find out that a replacement panel was sitting on a shelf forty feet away the whole time.
A checklist you can hold any help desk to
| Check | Ask the vendor | Test it in an hour | Where Maxdesk stands |
|---|---|---|---|
| Everybody signs in as themselves | Does each extra person cost money? | Count the logins against the people who answer mail | Unlimited agents on every plan, priced per workspace |
| Every reply names its sender | Can I see which person sent each reply? | Reply from two accounts, then read the thread | Each reply sits under the name of the person who sent it |
| Changes carry a name and a time | Which changes are written to the trail? | Change owner, status and priority from two accounts | Assignment, priority, status and internal notes, on every plan |
| The old value is kept | Does the trail show what a field was before? | Change the priority twice and read the trail | Yes |
| Internal notes are recorded | Are notes in the trail as well as replies? | Add a note, then find it in the trail | Yes |
| Rules are told apart from people | Can I tell a rule’s change from a person’s? | Build one rule, let it fire, then read the ticket | Rules keep their own runs log |
| Delete is its own permission | Who can delete a ticket? | Try deleting from an agent account | Delete tickets is a separate line in the permission matrix |
| Read-only access exists | Can somebody look without being able to reply? | Invite a read-only user and try to send | Read-only role included |
| Ticket scope can be limited | Can I limit which tickets one person sees? | Scope one user to one group and check their queue | Ticket scope per user |
| Custom roles can be built | Can I make a role between agent and admin? | Build one with no delete and no invite | Custom roles with a permission matrix |
| The trail lasts long enough | How far back can I see, and what happens after that? | Ask for the answer in writing | Rolling 3 months on Free, 12 on Pro, 24 on Elite; older data waits behind an upgrade |
| Views are recorded | Does the trail show who opened a ticket without changing it? | Open a ticket from a second account and look | Not something we claim; ask us in writing |
Testing a desk for all of this, ours included, takes about an hour with two accounts and a test customer address of your own. The question people most often forget to ask is the one about how long the record lasts. It only comes up the day a dispute arrives about something from last spring, and by then the desk is long since chosen.
Who on a small desk needs which permissions
The bookkeeper comes in on the last Friday of the month to match the refunds in Xero against a CSV of what Stripe actually paid out, and for two years she has done it by asking Hannah to forward her the threads. She needs to see every refund conversation and has no business replying to any of them. That is a read-only login, more or less exactly, and on a desk paying by the seat it is the login nobody buys. So the forwarding goes on, and Hannah loses an hour a month to it. Given a login of her own, the bookkeeper would do the whole of it her own self in twenty minutes.
Deleting does the most damage of anything in the wrong hands, and hardly ever on purpose. Somebody tidying the queue on a slow afternoon goes and deletes what looks like a duplicate, and it was the customer’s second mail, the one with the photo of the cracked panel attached. If only you and Hannah can delete, the duplicate gets closed instead, and the photo is still sitting there when the customer comes back in May.
Who gets to add people matters nearly as much, and so does who gets to touch the rules. On the greenhouse desk the answer to both ought to be you, and perhaps Hannah. A rule edited in a hurry can close forty mails before anybody notices a thing. And the temp who got a login for the December rush still has it in February, because taking a login away is a job that belongs to nobody. It gets done, to be honest with you, mostly on desks where the list of who can invite people is short enough to read in one go.
On five people a supervisor is often one role too many. It earns its keep the year somebody starts moving work between people and keeping an eye on everybody’s tickets without setting the place up, which on the greenhouse desk will be Hannah, probably, the spring after next. Custom roles wait longer again, mostly till somebody turns up who fits nothing you have, a contractor handling only trade orders, say, who wants scope over that one group of tickets and nothing else at all.
How do you tell a person’s change from a rule’s
At 02:14 one night in April a ticket on the greenhouse desk moved from Hannah to Leon. Nobody was awake. A rule did it, the one that sends anything from a trade customer’s domain to Leon, and Leon was four days into a fortnight in Crete, so the mail sat with him a good long while, well past any SLA the desk had set, until somebody noticed on the Thursday.
Had the trail put Hannah’s name on that move, or nobody’s, you would have spent the Thursday morning asking her why she handed it over. A proper trail says in so many words that a rule did it and which rule. The rules want a log of their own as well, showing each time they fired and each time they looked at a mail and let it go past, since the second half of that is what tells you why the 02:14 move happened and the one on the Wednesday did not. We wrote out a dozen routing rules worth copying on another page, and a log like that is how you check, a month in, that each one still does what you meant by it.
The same goes double for anything that sends replies on your behalf. If the greenhouse desk ever lets an AI agent answer the where-is-my-order mail, those replies want a name of their own in the record and never Hannah’s, and that is worth asking any vendor about in exactly those terms before the first one goes out.
How long does the record need to last
The screenshot turned up ten weeks after the reply went out. Ten weeks is nothing unusual, since a customer waits a while, chases once, waits again and only goes and digs out the screenshot when they have properly lost patience. Card disputes through Stripe can turn up later still. A customer in the UK or the EU can also ask under GDPR for the personal data you hold on them, conversation history included, and you have 1 month to hand the lot over.
Some regulated work asks for records going back years. Health information in the US under HIPAA is the example everybody reaches for, and that one gets its own page from us rather than a paragraph here, since what HIPAA asks of a business goes well past any trail.
On the greenhouse desk somebody went and looked back through the last year of complaints one wet afternoon to find the oldest, and it was a cold frame bought in September and argued about the following February, five months back. That is the shortest record that desk can live with, and it rules out anything that keeps three months, ours included on the free plan, which we come to in a minute.
What does this look like in Maxdesk
Run the same greenhouse desk on Maxdesk and the first thing that changes is the logins. The Saturday part-timer gets one, and so does Leon in the warehouse, since the bill is worked out per workspace, whatever the head count inside it. That one change does most of the work in this piece, truth be told, because a trail can only name people who signed in as themselves.
On the greenhouse ticket, Hannah’s change to the priority, Leon’s note at 11:05 and Mo’s reply at 16:42 would each sit under the right name, with the time beside it and whatever value it replaced. Replies sit under the name of whoever sent them as well, so the screenshot in May takes about as long to settle as it takes to search the customer’s address.
The bookkeeper gets the read-only role. Leon and the part-timer go in as agents, and you and Hannah as admins, which keeps deleting tickets and inviting people in two pairs of hands. If the trade contractor turns up, the permission matrix lets you build a role between agent and admin, and ticket scope keeps them inside the trade group and out of the rest of it. Our automation rules keep a runs log, which is the page you open when a ticket moved at 02:14 and nobody was up.
All of that comes on the free plan, the trail and the roles and the matrix along with it, and it sits in the very same ticketing system and shared inbox the team answers from, so nobody has a separate log to remember to fill in.
Our own record, and the places it stops short
The trail its self will tell you Mo sent the refund at 16:42. Whether he should have is still yours to sort out with Mo, over a cup of tea most likely, and we have no say in that bit of it at all.
We do not make anybody compliant with anything, plainly said. HIPAA and GDPR are about how a whole business handles information, and a help desk with a decent trail is one piece of evidence inside that, never the whole of it. An auditor asking whether your desk is compliant wants to see your written policies and talk to whoever runs the desk, and the name of a tool on its own will not get you far with them, ours or anybody’s.
Our trail, as we describe it on our own site, records changes, the assigning and the statuses and the notes and the rest. We have never claimed it keeps a list of who opened a ticket and read it without touching anything, and some audits care a great deal about exactly that, so if yours does, ask us in writing before you count on it.
Three months is what a free workspace holds, and the window rolls, tickets and reports and trail together. Anything older is kept rather than thrown away, and it opens up again with Pro at 12 months or Elite at 24, but a desk that needs last spring on screen on an ordinary Tuesday should start on a paid plan rather than move up the morning a dispute lands.
And we handle email only. A refund Leon promises a customer at the warehouse door goes on no trail of ours, and nor does anything said down the phone or on a Teams call with a trade customer. Hannah writes those up as a note on the ticket when she remembers, which is most days, and the odd one here and there slips by.
How would you test your own desk this week
Pull up the last ticket on your desk that ended with money going back to a customer. Then, from the record alone, try to name the person who first offered it and the time they did, and whoever agreed to it if that was somebody else. Do it your own self, without asking whoever usually knows these things. Put a timer on while you go.
Under 5 minutes and you are in decent shape, whatever tool is doing the recording. Walking to the kitchen to ask is the other way it goes, and plenty of desks end up there, and it is a great deal better found out on a quiet week in October than with a customer’s screenshot open on the screen in front of you.
While you are at it, count two numbers, the people who answer customer mail in a normal month and the logins your desk actually has. The greenhouse desk had five and one. The gap between your two is roughly how many people your record cannot name, and closing it costs nothing on our side of things, whichever plan you land on.
Common questions about help desk audit trails
What is a help desk audit trail?
A record kept on each ticket of every change made to it: which person or rule made the change, when, and what the field said before. A good one covers replies, assignments, priority and status changes and internal notes, so you can work out who promised a customer what without asking round the office.
Why does a shared email password break the audit trail?
Everybody signs in as the same account, so the record can only ever say the mailbox did it. Sign-in logs in Google Workspace or Microsoft 365 can show which device was used, not which person. Each person needs their own login before any trail can name them.
What permissions should a small support team set up?
Usually an admin or two, everyone else as an agent, and a read-only login for whoever reconciles refunds or checks quality. Keep deleting tickets, inviting people and editing automation rules with the admins, and add a custom role only when somebody fits none of those.
How long should a help desk keep its audit trail?
At least as far back as your oldest dispute in the last year. Under GDPR a person can ask for the personal data you hold on them and you have 1 month to respond; regulated work such as US healthcare under HIPAA can require years. Maxdesk keeps a rolling 3 months on Free, 12 months on Pro and 24 months on Elite, and nothing older is deleted.
Does an audit trail make a help desk HIPAA or GDPR compliant?
No. Compliance covers how a whole business handles information, and an audit trail is evidence that supports it. Ask any vendor exactly what their trail records, including whether it logs who viewed a ticket without changing it, and get the answer in writing.
Can you tell automated changes apart from changes made by a person?
You should be able to. A good trail names the rule that made a change, and the rules keep a log of each time they fired. In Maxdesk, automation rules have a runs log showing what fired, what did not and why.
Product details reviewed on 6 October 2026 against the live Maxdesk site. The greenhouse company, its people, the times and the $186 refund are made up for the example; the one-month window for a data access request is from Article 12(3) GDPR.
