Skip to content

Audit Log

The Audit Log helps administrators and security reviewers understand important activity across Studio.

What It Records

Audit events may include authentication activity, user and role changes, project workflow changes, evidence updates, finding updates, administrative configuration changes, token actions, and onboarding actions.

How To Use It

  1. Open Audit Log.
  2. Filter by user, event type, date range, project, or severity when available.
  3. Review the timestamp, actor, action, and affected resource.
  4. Investigate unexpected administrative or destructive actions.
  5. Cross-check suspicious events with application logs in Grafana or Loki.
  6. Preserve relevant records when supporting an incident or audit.

Investigation Workflow

  1. Identify the actor and affected resource.
  2. Confirm whether the action matches an approved workflow.
  3. Check surrounding events before and after the action.
  4. Review related project, evidence, or user records.
  5. Escalate if the event indicates unauthorized access or misuse.

Best Practices

  • Review high-impact administrative actions regularly.
  • Monitor role changes and user deactivations.
  • Preserve audit records for the required retention period.
  • Use audit logs alongside application logs and traces.
  • Document investigation outcomes when an event requires follow-up.