← System Documentation Results and disputes

Audit and records

Audit-ledger verification, protected records, notification evidence, retention and handover.

Audit and Records Guide

1. Audit ledger

CivitasVote records significant actions as keyed, hash-chained AuditEvent entries and tracks the ledger head. Events include actor, organisation, election, object type/identifier, request context, metadata, previous hash and event hash.

Run:

python manage.py verify_audit_ledger

A failed verification requires immediate investigation. Do not delete or edit audit rows to make the check pass.

2. Records to preserve

Preserve authorised-user and appointment history, voter directory, certified register and digest, nominations, candidate photographs, supporting documents, objections, complaints, evidence, incidents, ballot envelopes/selections, tally snapshots, approvals, declarations, notification records and release metadata according to policy.

3. Election-cycle deletion and historical status

An election cycle becomes an institutional record as soon as operational, voter, governance or dispute activity depends on it. Do not delete a cycle merely to remove it from an active list. Use cancellation, invalidation, historical filtering or a documented replacement relationship as applicable.

A controlled permanent deletion may be considered only for an unused Draft after the application confirms that no dependent electoral or audit-relevant record exists. The deletion event must be recorded outside the row being removed, or must preserve a sufficient immutable snapshot containing the election reference, association, title, actor, time, reason and related-record counts. Direct database deletion is prohibited.

A cancellation or invalidation is not a deletion. The system retains the election and writes ELECTION_CANCEL or ELECTION_INVALIDATE to the organisation-scoped audit ledger. The event metadata records the formal reason, previous status, terminal status and related critical-incident identifier. The election status change, incident and audit event are committed as one transaction so that a failed write does not leave a partial institutional record.

4. Public versus protected files

Public media may contain approved candidate photographs or association branding. Protected media includes appointment letters, imports, nomination evidence, complaint evidence and signed declarations. Access to protected files must pass through authorised views.

5. Notification outbox

The outbox records notification channel, recipient, subject/body, status, attempts, error and sent time. Dispatch through the scheduled command. Do not treat an outbox row as proof of delivery unless the status confirms success.

6. Retention

The association retention-days value guides retention but does not override petitions, audit, legal or governance holds. Before purge, make and test backups, confirm authority and retain evidence required by policy. Use the supported management command rather than manual deletion.

7. Officer access records

Appointments are retained after expiry or revocation. Read-only grace may permit limited inspection for seven days. Do not delete historical appointments, approvals or decisions merely to tidy lists.

8. Exports and handover

At closure, record the Git commit, deployment checksum, database backup, media backup, audit verification result, current tally version, signed declaration and unresolved disputes. Store the handover in approved institutional records.

Continue the procedure