Name the record and decision
Define the log category, written terms, deployment scope, configured period, retention authority, hold or deletion authority, and permitted expiry-verification procedure before collecting evidence. Distinguish application audit records from automation run history, system logs, backups, and analytics records. They can have different retention behavior and different operators.
Budibase's history documentation describes automation run history and a plan-dependent expiration boundary. That is a documented statement about one category, not proof of a configured customer account or a substitute for an application audit log. Use current official documentation as one source type, then retain it separately from configuration and lifecycle evidence.
Require equivalent observed evidence
For each eligible platform, use the same permitted synthetic record and capture the written retention terms, configured period, authorized configuration role, deletion or legal-hold path, and an approved expiry-verification procedure. Preserve documentation separately from a configured account view or authorized lifecycle observation. If a product does not expose an equivalent account, role, log category, policy scope, configuration value, or allowed verification path, mark that criterion unresolved.
Do not convert unavailable evidence into a score. A product can be considered later under a narrower decision, but it has not completed this comparison.
Use the fixed worksheet
The retention request below is deliberately a blank, no-score method: no account, role, log category, configuration, policy term, or lifecycle observation was available to freeze. Before applying it, explicitly freeze the same permitted synthetic record, account role, policy scope, configured-period request, lifecycle authority, and authorized expiry-verification procedure for every eligible product. Use the audit-log export evaluation only for the separate mechanics of exporting a log that is already available.
| Retention criterion | Fixed request before evidence collection | Do not infer |
|---|---|---|
| Log category | One named event category, event fields, and retrieval window. | That automation history equals an application audit log. |
| Written terms | Policy or documentation version, deployment scope, and access date. | That a vendor statement applies to the evaluated account. |
| Configuration and authority | Configured period, authorized role, and change or deletion authority. | That a default represents a customer's setting. |
| Hold and expiry verification | Approved lifecycle question and permitted synthetic-record procedure. | That a record will be retained or deleted without observing an authorized result. |
Evaluation checklist
- The required log category is named without substituting a different record type.
- Written terms, deployment scope, and log category are fixed.
- The same permitted synthetic record and authorized role are used for every product.
- Documentation, configuration, lifecycle authority, and observed expiry evidence are recorded separately.
- Missing comparable evidence ends the ranking rather than producing an inferred result.
Can vendor documentation establish a retention period for our account?
No. It can establish what the vendor says for a named product surface at an access date. Confirm the actual edition, deployment model, configuration, authorized role, and retained records before using it for a selection decision.