What You Can Do With It
- Answer “why was this person not created?” after a provisioning run.
- Find out who deactivated an account, and when.
- Check that a departure removed access straight away.
- Show an auditor how access is granted and removed.
What Is Recorded
Each entry records the time, the author, and what it affected. The author is a person, your identity provider, or Reelevant itself. Each entry also records whether it succeeded, plus an error reference when it failed.
Passwords, access keys, and single sign-on messages are never recorded. Sensitive values are replaced before an entry is saved.
Who Can See It
Anyone who can already administer identities in your company can read the audit log. In practice, this means anybody whose role can update users, roles, or Teams. There is nothing to switch on and no extra permission to grant. If you can invite and offboard people, you can read the log.Filtering The Entries
You can narrow the list down by:Good To Know
- The log is read-only. Nobody can edit or delete an entry, including administrators.
- Entries only cover your own company.
- Entries are kept for the retention period of your company, 90 days by default. Older entries are removed automatically.
- Export the entries you need before they expire if your company has to keep them longer.
What’s Next?
Automatic provisioning
Understand the provisioning events you see in the log.
Users
Invite, deactivate, and manage people.
Roles
Control who can administer identities, and therefore read this log.
Teams
Organise people into Teams for access control.