// Administration
Audit trail
An append-only record of every mutation made through the platform. Entries are written by the action itself, so the trail cannot drift from what actually happened.
10entries
Recent activity
10 entries
| When | Action | Actor | Resource | Detail |
|---|---|---|---|---|
| Incident Viewed | Viewer | Incident | ref: read-only access | |
| Alert Escalated | Analyst | Incident | rule: Impossible travel · riskScore: 92 | |
| Incident Note Added | Analyst | Incident | length: 142 | |
| Response Action Executed | Analyst | Incident | mode: SIMULATION · action: BLOCK_IP · target: 185.100.200.50 | |
| Response Action Executed | Analyst | Incident | mode: SIMULATION · action: DISABLE_ACCOUNT · target: jsmith | |
| User Role Change | Zain Khan | User | to: VIEWER · from: ANALYST · email: viewer@aegis.local | |
| Incident Status Change | Analyst | Incident | to: RESOLVED · from: INVESTIGATING · title: Bulk finance document collection followed by 1.2 GB egress | |
| Alert Status Change | Analyst | Alert | to: INVESTIGATING · from: NEW · title: Bulk document read on the Finance share | |
| Rule Disabled | Zain Khan | DetectionRule | name: Cloud access key created outside change hours · reason: Compliance evidence only, moved to reporting | |
| Settings Updated | Zain Khan | Setting | keys: ai.provider, ai.model |