Audit and Records Guide
1. Audit ledger
CivitasVote records significant actions as keyed, hash-chained AuditEvent entries and tracks the ledger head. Events include actor, organisation, election, object type/identifier, request context, metadata, previous hash and event hash.
Run:
python manage.py verify_audit_ledger
A failed verification requires immediate investigation. Do not delete or edit audit rows to make the check pass.
2. Records to preserve
Preserve authorised-user and appointment history, voter directory, certified register and digest, nominations, candidate photographs, supporting documents, objections, complaints, evidence, incidents, ballot envelopes/selections, tally snapshots, approvals, declarations, notification records and release metadata according to policy.
3. Election-cycle deletion and historical status
An election cycle becomes an institutional record as soon as operational, voter, governance or dispute activity depends on it. Do not delete a cycle merely to remove it from an active list. Use cancellation, invalidation, historical filtering or a documented replacement relationship as applicable.
A controlled permanent deletion may be considered only for an unused Draft after the application confirms that no dependent electoral or audit-relevant record exists. The deletion event must be recorded outside the row being removed, or must preserve a sufficient immutable snapshot containing the election reference, association, title, actor, time, reason and related-record counts. Direct database deletion is prohibited.
A cancellation or invalidation is not a deletion. The system retains the election and writes ELECTION_CANCEL or ELECTION_INVALIDATE to the organisation-scoped audit ledger. The event metadata records the formal reason, previous status, terminal status and related critical-incident identifier. The election status change, incident and audit event are committed as one transaction so that a failed write does not leave a partial institutional record.
4. Public versus protected files
Public media may contain approved candidate photographs or association branding. Protected media includes appointment letters, imports, nomination evidence, complaint evidence and signed declarations. Access to protected files must pass through authorised views.
5. Notification outbox
The outbox records notification channel, recipient, subject/body, status, attempts, error and sent time. Dispatch through the scheduled command. Do not treat an outbox row as proof of delivery unless the status confirms success.
6. Retention
The association retention-days value guides retention but does not override petitions, audit, legal or governance holds. Before purge, make and test backups, confirm authority and retain evidence required by policy. Use the supported management command rather than manual deletion.
7. Officer access records
Appointments are retained after expiry or revocation. Read-only grace may permit limited inspection for seven days. Do not delete historical appointments, approvals or decisions merely to tidy lists.
8. Exports and handover
At closure, record the Git commit, deployment checksum, database backup, media backup, audit verification result, current tally version, signed declaration and unresolved disputes. Store the handover in approved institutional records.