audit-trail.txt
Add an audit trail to <the records>: <paste the model and update code>

Record for every change: who, when, what changed — old and new values —
and where from (which endpoint or screen).

- Store it separately from the record itself, append-only.
- Never log passwords, tokens, or full payment details. Say what you
  excluded and how you'd handle a field that's sensitive but needs
  tracking.
- Make it queryable: everything one user did, and everything that
  happened to one record.
- Say how it grows and when I'd need to archive it.

Show me the screen that displays a record's history readably.

Capture the old value as well as the new. "Changed status" is much less useful than "changed status from pending to paid" when you're working out what went wrong.