Maintaining a clear and reliable audit trail for Qlik Cloud deployments is no longer optional for most organizations. Whether you operate in a regulated industry or simply want better visibility into who changed what and when, deployment tracking gives your team the accountability and confidence to move faster without losing control. This guide walks you through every step of setting up a complete audit trail for your Qlik Cloud environment, from initial prerequisites to sharing reports with stakeholders.
By the end of this process, you will have a structured, reviewable record of every deployment action, user change, and version update across your Qlik Cloud environment. Let’s get started.
What you need before enabling audit tracking
Before you configure any logging or tracking, make sure you have the right access and tools in place. Jumping into configuration without these prerequisites is the most common reason teams run into problems partway through the setup.
- Tenant Admin or Deployment Manager access rights in your Qlik Cloud environment
- A defined list of spaces and apps that fall within the scope of your audit trail
- Clarity on which compliance framework applies to your organization (for example, HIPAA, Sarbanes-Oxley, or an internal governance policy)
- A designated storage location or repository for audit log data
- Agreement from your team on who is responsible for reviewing and maintaining audit records
Once you have confirmed these items, you are ready to move into configuration. Skipping the scoping step in particular tends to create gaps in coverage that are difficult to close retroactively.
Configure deployment logging in PlatformManager
Configure your deployment logging settings so that every publish action, migration, and version change is captured automatically. This is the foundation of your Qlik Cloud audit log, and getting it right here saves significant effort later.
- Open PlatformManager and navigate to the governance and deployment settings for your Qlik Cloud connection.
- Enable deployment logging for each environment (development, test, production) that you want to track.
- Define the scope of logging: select the specific spaces, streams, or app groups that should be included in the audit trail.
- Set the logging granularity to capture both successful deployments and failed or rejected attempts, since failed actions are often the most important for compliance review.
- Save and apply your configuration, then trigger a test deployment to confirm that entries are being written to the log.
After completing this step, you should see a timestamped log entry for your test deployment. If no entry appears, verify that the correct environment is selected and that your user account has write permissions to the logging destination.
Capture user actions and version history automatically
Deployment logging alone is not enough. A complete ALM audit trail for Qlik Cloud also needs to capture individual user actions and the full version history of each app. This is what allows you to answer questions like “who approved this version?” or “what changed between version 3 and version 4?”
- Enable version control for each app within scope. Every save or publish action should create a new, uniquely identified version rather than overwriting the previous one.
- Activate user action tracking so that approvals, rejections, comments, and role-based actions are logged against individual user identities.
- Link version records to deployment records so that each deployment entry references the exact app version that was published.
With version history and user actions connected, your audit trail becomes a complete lifecycle record rather than a simple list of timestamps. You should be able to open any app and see a chronological history of every change, who made it, and whether it was approved before going live.
Structure your audit log for compliance requirements
Raw log data is useful for troubleshooting, but compliance reviewers and auditors need structured, readable records. Take time to organize your audit log in a way that maps directly to the requirements of your regulatory framework.
Most compliance frameworks, including those governing healthcare and financial data, require audit logs to capture at minimum: the identity of the actor, the action taken, the timestamp, the affected resource, and the outcome. Structure your log fields to match these categories explicitly rather than relying on free-text descriptions.
- Define a consistent naming convention for log entries so that automated filters can identify deployment events, approval events, and rollback events separately.
- Add metadata fields for environment (development, test, production), app owner, and applicable compliance tag where relevant.
- Configure retention settings so that logs are stored for the minimum period required by your compliance framework. Many frameworks require at least one year of retention, and some require longer.
Once your log structure is in place, run a sample query to confirm that you can filter by actor, date range, and event type in under a minute. If you cannot, revisit your field definitions and naming conventions before moving on.
Verify and review your audit trail records
Verification is the step most teams rush past, but it is the only way to confirm that your audit trail is complete, accurate, and trustworthy. An audit trail that has gaps or inconsistencies can actually create compliance risk rather than reduce it.
- Perform a reconciliation check: compare the number of deployments recorded in the log against the number of deployments executed over a defined test period. They should match exactly.
- Spot-check several individual log entries to confirm that user identity, timestamp, version reference, and outcome fields are all populated correctly.
- Simulate a rollback scenario and verify that the rollback action is captured as a discrete event in the audit log, linked to both the version being removed and the version being restored.
- Check that failed or rejected deployments appear in the log, not just successful ones.
If you discover gaps during reconciliation, trace them back to the configuration step and check whether any spaces or environments were excluded from the logging scope. Closing these gaps before your first formal compliance review is far easier than explaining them afterward.
Share and export audit reports for stakeholders
The final step is making your audit trail accessible to the people who need it, whether that is your internal compliance team, an external auditor, or senior stakeholders requesting a governance overview.
- Generate a lifecycle report that summarizes the full history of each app, including all version changes, approvals, and deployments. This is the document most auditors will request first.
- Export the report in a format appropriate for your audience. PDF works well for formal audits; CSV or Excel is more useful for internal analysis.
- Schedule recurring exports so that stakeholders receive updated reports automatically rather than making ad hoc requests to your BI team.
- Define access controls for the audit log itself, ensuring that reviewers can read records without being able to modify them.
With recurring exports configured and access controls in place, your audit trail becomes a living governance asset rather than a one-time compliance exercise. Stakeholders get the visibility they need, and your team spends less time fielding manual reporting requests.
How PlatformManager helps with Qlik Cloud audit trails
Setting up a complete audit trail manually is achievable, but it requires consistent discipline across every team member involved in your Qlik Cloud deployments. PlatformManager automates the most error-prone parts of this process so that governance becomes a natural outcome of your workflow rather than an extra burden on top of it.
- Automated deployment logging: Every publish action, migration, and rollback is captured automatically, with no manual entry required.
- Full version history: Every app version is stored and linked to the user who created or approved it, giving you a complete, auditable lifecycle record.
- Structured lifecycle reports: We generate compliance-ready reports that show the full history of each app, ready to share with auditors or internal stakeholders.
- Approval enforcement: Deployment steps require sign-off before anything goes live, ensuring that your audit trail reflects a controlled, accountable process from start to finish.
- Regulatory compliance support: We fully meet requirements such as HIPAA and Sarbanes-Oxley, making PlatformManager a reliable foundation for organizations in regulated industries.
If you want to see how this works in practice, explore our BI governance solutions or get in touch with us to start a free three-day trial with full access to a cloud server, including a demo collection of apps and data.