One audit trail, every product
Why attribution belongs in the platform, not in each product's backlog.
Every operational product we build eventually gets the same question from a customer: who changed this, and when? It arrives late, usually during a procurement review, and it is expensive to answer if you did not plan for it.
We used to treat that as a per-product feature. HRMS grew an activity log. InsuraVault needed a stricter one for regulatory reasons. Lever Today's audit history was really its core object rather than a side table. Three products, three schemas, three answers to the same question — and no way to reason about any of them together.
Attribution is now part of the shared foundation. A product declares which records are auditable; the platform handles capture, retention and query. What a product still owns is what the entries mean — an approval in Lever Today reads differently from a policy endorsement in InsuraVault, and that framing is product work, not platform work.
The line we settled on: the platform owns the mechanism, the product owns the meaning. It has held for notifications and reporting too, which is a reasonable sign it is the right seam.