Sample audit record
This is what proof looks like in HartBeat: records from one contractor session, with the person, the instrument, the HART command, the policy decision, and whether it was carried out. Illustrative record; the organization, people, and devices are fictional.
What every record answers
| A reviewer asks | The record holds |
|---|---|
| When? | Precise timestamp |
| Who? | The named person and their role |
| Where? | Organization, site, gateway, and device |
| In which session? | The remote work session it belonged to |
| What? | The HART command, by number and human-readable name, and its category |
| Under what authority? | The policy that evaluated it, the decision, and the reason |
| What happened? | Whether the command was carried out |
| Can I trust it? | A digital signature, and a link to the previous record that makes gaps or edits detectable |
One contractor session
The first record is a read the policy allows. The second is a write the policy denies: HartBeat flags it and records it permanently. The third closes the session.
- When
- 14:32:07.418
- Who
- [email protected] (Contractor)
- In which session
- Remote support session #1182
- Where
- North Pump Station, Gateway 2
- Device
- LT-204, radar level transmitter
- What
- 1 Read Primary Variable Read
- Outcome
- Carried out
- Under what authority
- Allow read commands permitted for contractors
- Can I trust it?
- ✓ Signed✓ Chained to previous record
- When
- 14:33:52.106
- Who
- [email protected] (Contractor)
- In which session
- Remote support session #1182
- Where
- North Pump Station, Gateway 2
- Device
- LT-204, radar level transmitter
- What
- 35 Write Range Values Write
- Outcome
- Recorded, not blocked
- Under what authority
- Deny write commands not permitted for contractors
- Can I trust it?
- ✓ Signed✓ Chained to previous record
- When
- 14:34:10.772
- Who
- [email protected] (Contractor)
- In which session
- Session #1182 ended
- What
- Session closed by the contractor
- Can I trust it?
- ✓ Signed✓ Chained to previous record
Try to change the record
Rewrite the second record’s decision from Deny to Allow and see what a reviewer would see.
Tamper-evident, in plain language
Every out-of-policy command is flagged and permanently recorded.
Each record is digitally signed when it is written and carries a fingerprint of the record before it, so the records form an unbroken chain. If anyone edits, deletes, or reorders a record later, the signature or the chain no longer checks out, and the change is detectable. Integrity is mathematical, not “we promise we keep logs.”
Download the sample (CSV, fictional data)
The sample is spreadsheet-ready, like a real export from HartBeat.
Want to see it with your own instruments?
Contact sales and we’ll scope a trial with you.
Set up a trial with our team.
Contact sales to set up a trial: for distributed operators, service teams, and instrumentation groups ready to evaluate governed remote HART access.