Audit history: trace what happened, event by event

VaultPilot records supported authentication, vault, sharing, extension, directory, update, configuration, and security events with their context. Keep audit exports and event details private, and redact anything you share.

Purpose
Operational review
Content
Actor, target, role, time, metadata
Integrity
Current and previous hash on each event
Illustration of findings narrowing into reviewed records

What an event detail shows

The detail drawer shows the actor, target, role, time, operation metadata, and the event's current and previous hash. With filters and search, you can find one incident or change without opening the database.

When the chain looks partial

The Overview security posture shows whether the audit chain verified. The Audit Log screen does not calculate a chain state; there you compare the current and previous hash of adjacent events by hand. A filter can produce a partial view, so rule that out first. If the warning remains, keep the current state and follow the documented recovery path. Do not hide or rewrite the condition.

Limits to know

  • Audit history covers supported events, not every endpoint or every action in outside systems.
  • A healthy chain shows only that the sequence is consistent. It does not show that each action was appropriate, and it is not a compliance document or legal evidence.
  • When an investigation reaches beyond VaultPilot, you also need the records of those other systems.

Check step by step

  1. 01

    Define the time window, user, area, and expected action.

  2. 02

    Filter the audit view and open the relevant event detail.

  3. 03

    Check the chain state in the Overview security posture before you rely on the sequence.

  4. 04

    Keep plaintext secrets, master passwords, private keys, and package contents out of any audit material you share.

Read more in the guides: Audit and security posture, Audit Log screen guide, Partial audit chain recovery