Because without it the person with the strongest memory wins. A close date that moved, a discount that was approved, a permission that was granted — all become matters of recollection rather than record.
The audit trail records every change to every record: the actor, the timestamp, the field, the previous value and the new one, including changes made through the API.
The trail is written on change and is not editable by anyone, including administrators. It covers custom fields, permission changes, merges, imports and automated changes, each attributed to the person or token that made them.
A customer disputed an agreed discount. The trail showed the rate changed at 16:20 on a Thursday by a named person, with the approval recorded eleven minutes later. The conversation took four minutes.
It is not a version-control system for documents — quote versions handle that — and it is not a security monitoring tool. It is the record of what changed, which is a prerequisite for both.
Record permissions changes, duplicate merges, import commits, automation runs and API writes all appear in it, and exports of it can be scheduled for whoever needs them.
No. An audit trail an admin can edit is not an audit trail.
Yes, attributed to the token and the user behind it.
For the life of the record, subject to the retention policy you set.
Fourteen days, every module, no card. Or half an hour with someone who will run it on your own records and tell you where it does not help.