A client asks it during a security review. An auditor asks it in week two. Sometimes an incident asks it for you, at eleven on a Friday evening.
Who opened this, and when?
In most companies the honest answer is a shrug, followed by a week of asking around. And the moment you cannot answer, a technical gap turns into a personal one: it is your company, so it is your answer.
Answer from a record instead of from memory
The reason nobody can answer is not carelessness. It is that the question was never written down anywhere.
A shared vault knows who has an account. A spreadsheet knows nothing at all. A file on a drive tells you when it was last modified, which is not the same as who read it. Reading leaves no trace, so the most important event of all is the one nobody logs.
In Inheriti® Business the opposite is true. Every access request, every approval, and every reveal is written down as it happens, in your organisation’s audit trail, next to authentication, moderation, data asset, membership, storage and subscription events.
So the answer to “who opened this, and when” is not a recollection. It is a line with a name, a role, a timestamp and the plan it belongs to.

Know exactly what to rotate after an incident
The expensive part of a breach is rarely the breach. It is the fog afterwards.
Nobody knows which credentials were exposed, so the safe assumption is all of them. Weeks go into rotating everything, badly, while the business waits. Half of it was never at risk, and you will never know which half.
With a record of who requested, who approved and what was revealed, that becomes a short list instead of a guessing game. You rotate what was actually opened.
Hand over a report that proves it was not edited
An export that anyone could have edited in a text editor is not evidence, it is a document.
Every report closes with an integrity page: a SHA-256 hash of the document, its reference and its scope. The person receiving it can check that what they are reading is what was produced. It turns “here is our log” into something an auditor can lean on.
One deliberate limitation is worth knowing: the plan register inside a report describes configuration only, never protected content. The report proves who did what. It never becomes a second copy of your secrets.
Scope the log to one member, one team or one plan
“Send us your logs” usually means a dump nobody reads.
The trail can be scoped before it is exported: a single member, a single team, a single plan or a single storage layer. A supplier review about one system gets exactly that system, and nothing else about your company travels with it.
Prove the rule, not just the event
There is a second thing an auditor almost always asks: not only what happened, but what would have happened.
Because governance lives in the plan, that is readable too: which teams have access, who the moderators are, how many approvals are required, and how the Dead Man Switch is configured. The rule is written down where it is enforced, which is the only place a rule can be checked honestly.
What Inheriti® Business does about it, and why you need it
“Who opened this, and when” is not a hard question. It is an unanswerable one, because the event that matters most, reading, leaves no trace anywhere else.
Inheriti® Business writes it down where it happens:
- Requests, approvals and reveals are recorded as they occur, with the person, the role, the time and the plan.
- Reports prove they were not edited, through an integrity page carrying a SHA-256 hash of the document and its scope.
- The trail can be scoped to one member, one team, one plan or one storage layer, so an audit about one system gets exactly that system.
- The rule is readable too. Teams, moderators, approval thresholds and the Dead Man Switch configuration live in the plan where they are enforced.
- The plan register never becomes a second copy of your secrets. It describes configuration only.
That is the difference between saying you have control and being able to show it.
Start with the accounts an auditor will ask about first
You do not need to move everything to have an answer.
Pick the three accounts with the most outside interest. Banking, the customer database, the payroll portal. Those are the ones a client or an auditor asks about.
Put them in plans in Inheriti® Business with the teams and approvals that reflect how you actually work.
Export the trail once, now, while nothing is wrong. Reading it in a quiet week tells you more than reading it during an incident, and it shows you which questions you can already answer.
From then on, the question that used to cost a week takes a few seconds. See how Inheriti® Business works.