# Security and Auditing

**URL:** https://discuss.tryton.org/t/security-and-auditing/2008
**Category:** Ideas
**Created:** [November 27, 2019, 4:06pm UTC](https://discuss.tryton.org/t/security-and-auditing/2008 "2019-11-27T16:06:15Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![2cadz](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/2cadz/32/130_2.png) [@2cadz](https://discuss.tryton.org/u/2cadz)
#### Post date: [November 27, 2019, 4:06pm UTC](https://discuss.tryton.org/t/security-and-auditing/2008/1 "2019-11-27T16:06:15Z")

</div>

Hi,

I have the question quite regularly, is it possible to follow the modifications of some objects or some fields.  
I know that this feature can have a serious impact on performance, but for sensitive data I think the performance cost can be accepted.  
What would be the best way for you to implement this feature?  
My first idea would be to add a ‘track’ attribute (by default to False) on certain fields and to write in an audit table (what, who, when and if possible the written value).  
What do you think ?

Regard

---

<div class="post-metadata">

### Author: ![albert](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/albert/32/21_2.png) [@albert](https://discuss.tryton.org/u/albert)
#### Post date: [November 27, 2019, 4:39pm UTC](https://discuss.tryton.org/t/security-and-auditing/2008/2 "2019-11-27T16:39:48Z")

</div>

In Tryton you can add the “\_history = True” [attribute to models](http://docs.tryton.org/projects/server/en/latest/ref/models/models.html#trytond.model.ModelSQL._history) which will keep the whole history of changes for all records in the model.

We created a couple of modules to give better auditing possibilities which uses the history of those models that have it enabled.

The [audit\_log](https://bitbucket.org/nantic/trytond-audit_log) module allows you to see who changed what during a period of time.

The [audit\_trail](https://bitbucket.org/nantic/trytond-audit_trail) simply tells who and when logged in/out of the system.

---

<div class="post-metadata">

### Author: ![2cadz](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/2cadz/32/130_2.png) [@2cadz](https://discuss.tryton.org/u/2cadz)
#### Post date: [November 27, 2019, 5:02pm UTC](https://discuss.tryton.org/t/security-and-auditing/2008/3 "2019-11-27T17:02:45Z")

</div>

Thank you Albert I look on this side.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [November 27, 2019, 6:45pm UTC](https://discuss.tryton.org/t/security-and-auditing/2008/4 "2019-11-27T18:45:18Z")

</div>

If you want to see who accessed/processed what and when, you can also use the logging feature. It is possible to register a log handler to store the log INFO generated by `trytond.protocols.dispatcher`. This will give you all the information.

---

<div class="post-metadata">

### Author: ![2cadz](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/2cadz/32/130_2.png) [@2cadz](https://discuss.tryton.org/u/2cadz)
#### Post date: [November 28, 2019, 10:11am UTC](https://discuss.tryton.org/t/security-and-auditing/2008/5 "2019-11-28T10:11:27Z")

</div>

Thank you, I will test that too.
