Using the QuickBooks Desktop Audit Trail to Find Who Changed or Deleted a Transaction
When a transaction has been modified or removed and you need to know who did it and when, the Audit Trail report is the first place to look.
QuickBooks Desktop keeps a running log of every transaction that is added, changed, or deleted, along with the user who performed the action and the exact date and time. When a number on a report does not match your expectations, or an invoice or check has vanished from the register, the Audit Trail report is the fastest way to narrow down what happened. This guide walks through pulling the report, filtering it, and reading the entries so you can pinpoint the event.
Preconditions
The Audit Trail must be turned on. In most QuickBooks Desktop editions it is enabled by default and cannot be disabled, but it is worth confirming:
- Sign in to the company file as the Admin.
- Go to Edit > Preferences.
- Select Accounting on the left, then click the Company Preferences tab.
- Confirm that Use Audit Trail is checked.
You do not need single-user mode to run the report, but you do need sufficient permissions. Standard users can typically view the Audit Trail; if a user sees a permissions error, the Admin must grant access to sensitive accounting reports.
Pulling and Filtering the Report
- From the top menu, select Reports > Accountant & Taxes > Audit Trail.
- Click Dates (or the date-range button at the top of the report) and set the range that covers when you believe the change occurred. If you are unsure, widen the range — a broad search is slower but safer.
- Click Filters to narrow the results further:
- Entered/Last Modified — set this to the same date range as above so the report shows events by when the edit happened, not just the transaction date.
- Changed/Modified By — if you suspect a specific user, select that user name from the drop-down. To search everyone, leave it at All users.
- Transaction Type — if you know you are looking for a deleted check or a modified invoice, filter by that type to reduce noise.
- Click OK to apply the filters and generate the report.
Interpreting the Results
Each line in the Audit Trail represents one state of a transaction. Read the leftmost columns carefully:
- Date is the transaction date — the date printed on the invoice or check.
- Last Modified By shows the user name of the person who made the most recent change.
- Last Modified Date and Last Modified Time tell you exactly when that change was saved.
- State is the critical column. It can read Prior, Latest, or Deleted.
A Prior entry is a snapshot of what the transaction looked like before a change. A Latest entry is the current version. If you see a pair of rows for the same transaction — one marked Prior and one marked Latest — compare the amounts, accounts, or items between them to see exactly what was changed.
A Deleted entry means the transaction was removed entirely. The row remains in the Audit Trail so you can see who deleted it and when, but the transaction no longer exists in the live file. The amount will often appear in the report's totals, which can be confusing; remember that the Audit Trail shows historical activity, not just current balances.
Signs It Worked
You will know the report has served its purpose when you can answer three questions: which transaction was affected, which user performed the action, and the date and time it happened. Note the transaction type, number, and date for your records.
Where the Audit Trail Stops Short
The Audit Trail captures changes made inside QuickBooks after the feature was enabled. It does not record edits made at the database level by third-party tools, and it does not retroactively log activity from before it was turned on. If a transaction was deleted and later restored from a backup, the restored copy will show a new creation date rather than the original one. In files where the Audit Trail itself has been damaged or where transactions were removed through data corruption rather than user action, the report may be incomplete. In those situations our engineers can perform a forensic review of the company file to reconstruct what happened from the underlying transaction data and the .TLG transaction log.