Broker guides

Who Changed This Load? A Freight Broker TMS Audit-History Test

# Who Changed This Load? A Freight Broker TMS Audit-History Test

A load can look correct now and still leave an owner unable to explain how it got there. The customer rate changed. A stop moved. The carrier cost no longer matches the confirmation. A document was replaced. The load was voided, reopened, or reassigned. When someone asks what happened, a current-value screen is not enough.

That is the buying question behind a freight broker TMS audit trail: Can a second person reconstruct a material change without relying on the person who made it?

Use this controlled, two-user test before trusting an activity-history claim. It is an original product-evaluation method—not an industry standard, legal opinion, security audit, or representation of ServeOps functionality.

First, separate four different kinds of history

“Audit trail” is too broad to score as one checkbox. Ask the vendor to demonstrate each layer separately:

  1. Record-change history: which field changed, its prior value, its new value, the user, and the timestamp.
  2. Workflow history: status changes, assignments, holds, approvals, voids, reopenings, and other lifecycle events.
  3. Document history: which version was generated, uploaded, sent, replaced, or superseded—and whether an older version remains identifiable.
  4. Security or session logs: sign-ins, failed attempts, session details, device information, and administrator actions.

A product may support one layer without supporting the other three. A note saying “rate updated” is not field-level history. A file’s upload time is not proof of who changed the load. A security log is not a document version record.

<!-- Visual placement: assets/01-four-history-layers.svg -->

Define a six-part evidence record

For every material event, try to recover six facts:

  • Object: the load, stop, charge, document, carrier assignment, invoice, or payable affected.
  • Before: the prior value or identifiable prior state.
  • After: the new value or current state.
  • Actor: the named user, integration, system process, or clearly labeled unknown source.
  • Time: a precise timestamp with a clear timezone.
  • Context: the reason, source document, approval, note, or related event that explains the change.

Do not award a pass because the team can infer an answer. The record should show it. If the answer comes from email, a spreadsheet, or a separate administrator export, label the step Manual and name that source.

Run the two-user, three-load test

Use synthetic or properly authorized records. Never alter a live shipment merely to test history.

Load 1: ordinary correction

User A creates a representative load. User B then changes one customer reference, corrects one facility contact, and updates one nonfinancial note.

After signing in separately, User A should be able to identify each changed object, before-and-after value, User B as the actor, the timestamp, and any supplied reason. Check whether unrelated noise buries the changes and whether the history can be filtered to this load.

Load 2: post-dispatch commercial change

Create a second synthetic load with a carrier assigned and a rate confirmation generated, if the product supports those steps. User B changes one carrier-cost value and one pickup window, then creates or uploads the revised supporting document.

Now test the relationship among the records. Can User A tell which commercial value changed, whether the prior value remains visible, which document corresponds to the current value, whether the older document is clearly superseded, and who performed each action? A timestamped current document alone does not prove the earlier state.

Keep this test distinct from the dedicated appointment-change-log test, which owns requested, confirmed, estimated, and actual time evidence. Here, the narrow question is whether the broader change sequence can be reconstructed.

Load 3: reversal and boundary case

Use a third synthetic load to test the actions most likely to disappear from a clean demo. Depending on authorized product behavior, change an assignment, void and restore a record, replace an attachment, or remove a test value. Do not delete anything irrecoverable.

Check whether the event remains visible after the reversal; whether “deleted,” “voided,” “removed,” and “replaced” are distinguishable; whether an administrator sees more history than a dispatcher; and whether an export preserves the same meaning as the on-screen view. If the product cannot safely run an action, mark it Not tested—not Pass.

<!-- Visual placement: assets/02-three-load-reconstruction-scorecard.svg -->

Make a cold handoff prove the result

Give a third reviewer the three load IDs and no verbal explanation. Ask the reviewer to answer:

  1. What material values changed?
  2. What were the prior and current values?
  3. Who or what made each change?
  4. When did it happen, in what order, and in which timezone?
  5. Which note, approval, or document explains it?
  6. Which version is operative now?
  7. Did any deletion, void, reversal, or replacement occur?
  8. What part of the answer still lives outside the TMS?

Score each answer:

  • Pass: visible and attributable in saved evidence.
  • Manual: recoverable only through a named external or administrative step.
  • Fail: missing, contradictory, or impossible to reconstruct.
  • Not tested: the scenario was not safely demonstrated.

Reject the broad audit-history requirement if material edits overwrite the only prior value, the current document cannot be distinguished from a stale copy, actions share a generic user identity, timestamps cannot be ordered reliably, or a reviewer needs the editor’s memory to explain the record.

Ask about retention, access, and export separately

History that appears today may not remain available for the period your brokerage requires. Obtain written answers for retention duration, plan limits, archive behavior, role-based visibility, administrator access, deactivated users, export format, vendor support access, timezone handling, and what happens after cancellation or migration.

Do not assume that an exported load table includes change events. Do not assume a backup is a searchable audit trail. Do not assume “immutable” unless the vendor defines the technical control and provides evidence appropriate to your review.

For broader access testing, use the freight broker TMS permissions test. For regulatory transaction-file scope, use the separate three-year recordkeeping checklist. If you are switching systems, add these event-history fields to the TMS migration checklist.

Public facts and product claims are not the same

Current 49 CFR § 371.3 requires a broker to keep a record of each transaction with specified information and retain the required record for three years. It does not prescribe this six-part change record, require a user-by-user TMS audit trail, or certify that passing this test satisfies a brokerage’s legal duties.

NIST Special Publication 800-92 is general computer-security guidance about log-management infrastructure and processes. It is not freight-broker regulation and does not certify any TMS. Current vendor materials from LoadStop and BrokerPro show that activity history, audit trails, document versions, and timestamps are active product-evaluation themes; those are vendor descriptions, not independent proof that a particular system performs them.

Verified ServeOps functionality: this guide makes no claim that ServeOps provides field-level history, prior values, document versioning, deletion recovery, session monitoring, immutable logs, alerts, approvals, retention guarantees, audit exports, or compliance controls. Every behavior above is a requirement to demonstrate and score.

If ServeOps is on your shortlist, run the test with synthetic or properly authorized records and treat every unverified behavior as Not tested. The verified offer language is unchanged: 60-day free trial; card collected upfront; no charge for 60 days; cancel anytime; then $49 per seat/month or $490 per seat/year. Card is required upfront. No charge during the trial. Confirm the complete checkout terms before signup.

Start the controlled evaluation only when your team is ready to preserve the evidence and score the result.

Sources

  1. Electronic Code of Federal Regulations, 49 CFR § 371.3 — Records to be kept by brokers, accessed August 26, 2026.
  2. National Institute of Standards and Technology, SP 800-92: Guide to Computer Security Log Management, current publication page accessed August 26, 2026.
  3. LoadStop, Data Security in Cloud-Based TMS Platforms: What Carriers and Brokers Should Know, accessed August 26, 2026. Vendor-authored market signal only.
  4. BrokerPro, Freight Broker Document Management, accessed August 26, 2026. Vendor-authored market signal only.
  5. ServeOps, registration page, accessed August 26, 2026. Visible page confirms the 60-day trial, no-charge period, and cancel-anytime language; card and pricing terms require a complete checkout recheck before publication.