Data Access Audit Trail
Every access to district data is recorded in a hash-chained, tamper-evident log. Whether that chain is intact is published on the dashboard overview, together with counts of what kinds of access occurred.
Individual access records are restricted
What is public: that the chain is intact, how many entries it holds, and how many accesses occurred today by kind — published on the dashboard overview. That is the part which proves the log has not been altered.
What is held back: the entries themselves. Each one names what was read and when, and a record-by-record feed on a public page would expose the District’s access patterns even with roles standing in for names.
Where the line is drawn: reading individual entries requires district-administrator authority, which the data platform grants to a named person and checks on every request. This public surface has no sign-in, so it cannot present such a person, and it deliberately holds no credential that would stand in for one. That is the boundary, not a gap waiting on configuration. If you hold that authority, the ledger is one click away in the district workspace.
Open the audit ledger in the district workspaceRequires district-administrator authority · sign-in at rcsd.vforce360.ai
This is an audience restriction, not privacy suppression. Signing in never reveals a figure withheld under the reporting threshold — those are protected from every audience, including the District’s own staff.