100%. My work has really great auditing tools. I use them often to understand actions by other that are routine. It still doesn't prevent a employee emailing a datacenter to rack a malicious device or give someone service without paying. Record trails are not auditing. They are records.
Auditing, post mortems, whatever diagnose the situation afterwards.
At the end of the day Uber can't stop a driver from kidnapping people, but it can provide documentation and gps coordinates to police.
My point is companies need reasonable records and audit policies and when _really bad stuff happens_ you call in the big guns for the arm of the law.
At some point you also need to trust staff and weigh that against mistakes and malicious intent.
In short, security remains an imperfect balance of practicality