The audit trail is the part of proofing nobody thinks about until the one afternoon it decides who pays. Five thousand leaflets are boxed, the customer is looking at a phone number that is two digits wrong, and the sentence arrives: that is not what I approved.
At that point you are not having a design conversation. You are producing evidence, and what you have is a thread.

What a thread proves, and what it does not
An email approval usually contains the word "approved" and nothing else that survives contact with a dispute.
It does not say which file. "Looks good" sits under whichever attachment was open when they typed it, and by round three there are three PDFs in the thread with two different names. Attachment order in a forwarded chain is not evidence of anything.
It does not say the file was unchanged afterwards. The most dangerous edit in any shop is the small correction made after the yes — usually right, usually two minutes' work, and completely uncovered by the approval you are holding.
It does not say who. The reply came from the person who was in the thread, which is not the same as the person entitled to commit their company to a print run. On sign and packaging work it frequently is not.
It does not say what they were shown. On a twelve-page menu, "approved" from someone who opened page one is a different fact from "approved" by someone who paged through to the end. The inbox cannot tell the two apart, and neither can you.
The five facts worth keeping
An approval is useful later in proportion to how many of these it nails down.
1. The exact file — by content, not by name. A filename is a label anybody can reuse; two different PDFs called menu-v2.pdf are the normal case, not the exotic one. What identifies a file beyond argument is its content: a checksum, or failing that, the stored original itself, untouched since it was sent.
2. The person, identified well enough to be recognised. A name and an address they answered from. Not "the client".
3. The time. Which round it belonged to, and — this is the part people skip — whether anything happened to the artwork after it.
4. The scope of what was shown. Every page, or the first one. The whole run, or one item of it. An approval that does not state its scope gets read generously by whoever needs it to be generous.
5. Whatever terms it was given under. If your terms cover colour tolerance, reprints or turnaround, an approval given without them attached is an approval given without them.
Keeping the trail without buying anything
Four habits get you most of the way, and they cost nothing but discipline.
Never re-export over a version number. A version number is used exactly once. Re-saving v2 because "it is basically the same" is how one name comes to mean two files, which is how the whole trail dissolves. The mechanics are in our guide on not printing the wrong version.
Ask for the version in the yes. "APPROVED v3" instead of "approved" is one extra word for the customer and the difference between a fact and an impression. The artwork approval email templates ask for it in a way people actually comply with.
Write back a verbal yes the same hour. Approvals arrive by phone, at a counter, from a van. That is fine as long as it does not stay verbal: confirming you approved alder-fascia-v3.pdf today at 15:40, going to production on that basis. Sent, not just noted.
Keep the sent file, not a regenerated one. The copy that went out is the artefact. An export made afterwards from the same layout file is a different file, and a checksum will say so even when your eyes cannot.
Or put all four on one page. A design sign-off sheet is the paper version of this list — version, date, who approved, what they approved, signed — and for a yes given at a counter or beside a van it is often the only trail that actually gets kept.
Done consistently, this is a real audit trail. Its weakness is not rigour — it is that every step depends on a person doing it on a busy day, and the day it gets skipped is statistically the day it was needed.
What a system can settle that a habit cannot
This is our own product, so weigh the paragraph accordingly.
Proofavo records an approval against the exact, immutable file the customer opened, and issues a downloadable approval record naming the version, the person and the time, with a SHA-256 fingerprint of the approved artwork. Approval records are append-only: they are not edited afterwards, by us or by you.
Three things in it exist specifically because of the failures above:
- A proof with an unresolved comment cannot be approved. The "approved, but…" that turns into an argument has nowhere to live.
- On a multi-page proof, the approval dialog states how many pages have actually been opened — so scope is recorded rather than assumed.
- On Professional, the record can carry your own terms: the customer ticks a separate box accepting a named version of your terms PDF, and the record states that version and its SHA-256. The expanded record also includes the rounds in the customer's own words, and which pages were argued over.
You can run the whole loop in the live demo without signing up; the approval at the end produces a real record you can download and read.
The honest limit: this is operational evidence, not a qualified electronic signature. It shows what was approved, by whom, when, and that the file has not changed since. If your situation requires a qualified signature under eIDAS or an equivalent regime, this is not that, and it is not offered as that.