// Administration

Audit trail

An append-only record of every mutation made through the platform. Entries are written by the action itself, so the trail cannot drift from what actually happened.

10entries

Recent activity

10 entries

WhenActionActorResourceDetail
Incident ViewedViewerIncidentref: read-only access
Alert EscalatedAnalystIncidentrule: Impossible travel · riskScore: 92
Incident Note AddedAnalystIncidentlength: 142
Response Action ExecutedAnalystIncidentmode: SIMULATION · action: BLOCK_IP · target: 185.100.200.50
Response Action ExecutedAnalystIncidentmode: SIMULATION · action: DISABLE_ACCOUNT · target: jsmith
User Role ChangeZain KhanUserto: VIEWER · from: ANALYST · email: viewer@aegis.local
Incident Status ChangeAnalystIncidentto: RESOLVED · from: INVESTIGATING · title: Bulk finance document collection followed by 1.2 GB egress
Alert Status ChangeAnalystAlertto: INVESTIGATING · from: NEW · title: Bulk document read on the Finance share
Rule DisabledZain KhanDetectionRulename: Cloud access key created outside change hours · reason: Compliance evidence only, moved to reporting
Settings UpdatedZain KhanSettingkeys: ai.provider, ai.model