Field Manual PHP / Laravel reference
← Security

Audit trails

Audit records document who did what, when, and to which entity.

What it is

Audit records document who did what, when, and to which entity.

When to use it

Persist attributable records for important state changes.

Syntax

DB::table("audit_logs")->insert(["actor_id" => $user->id, "action" => "order.cancelled", "subject_id" => $order->id, "created_at" => now()]);

Example

DB::transaction(function () use ($order, $user) {
    $order->status = "cancelled";
    $order->save();
    DB::table("audit_logs")->insert([
        "actor_id" => $user->id, "action" => "order.cancelled",
        "subject_id" => $order->id, "created_at" => now(),
    ]);
});

Common mistakes

Ordinary application logs are not an immutable audit system; restrict write/delete access and record correlation IDs.

Related topics

Audit trails