Early access for UK transport operators View the Founding Customer Programme

Audit & traceability policy

GLS is designed so that operational activity can be traced, reconstructed and evidenced where required for regulatory, contractual or safety purposes.

Version: 0.6 Last reviewed: Jan 2026 Review cycle: Annual or upon material change

Purpose

This policy describes how GLS supports traceability of user and system actions. The intention is to make regulatory or customer audits manageable, and to help operators investigate incidents in a structured way.

Scope

This policy applies to all operational features within GLS where user or system actions materially affect freight activity, data integrity or commercial outcomes.

Principles

  • Users should be clearly associated with the actions they perform
  • Important actions should be time-sequenced and recoverable
  • Logs should support investigation without exposing unrelated data
  • Traceability should not depend on manual effort

Audit-oriented behaviour in GLS

Action traceability

Key operational actions — including creation, update and lifecycle changes — are recorded with identity, time and context information so that activity can be reconstructed if required.

Event logging

Logs are stored in a time-ordered manner to support forensic review and incident response. Sensitive data is handled in accordance with the Data Protection Policy.

Tenant separation

Logs generated by one tenant are not available to another tenant, reflecting both privacy expectations and contractual boundaries.

Operational transparency

GLS aims to provide operators with views and exports that align to what auditors, safety inspectors and regulators typically request. This will continue to develop over time.

Use in investigations

Logs and traceability features are designed to support:

  • regulatory audits
  • customer contract verification
  • incident and complaint investigations
  • internal quality reviews

Responsibilities

GLS provides the platform-level capability for traceability. Customers remain responsible for the appropriate assignment of roles, permissions and internal approval processes.

Limitations

Traceability does not replace management oversight or operational supervision. Logs are not intended for covert surveillance of individuals and must be used ethically and lawfully.

Review

This policy is reviewed at least annually, or sooner if platform architecture or regulatory expectations change materially.