Audit history: trace what happened, event by event
VaultPilot records supported authentication, vault, sharing, extension, directory, update, configuration, and security events with their context. Keep audit exports and event details private, and redact anything you share.
- Purpose
- Operational review
- Content
- Actor, target, role, time, metadata
- Integrity
- Current and previous hash on each event

What an event detail shows
The detail drawer shows the actor, target, role, time, operation metadata, and the event's current and previous hash. With filters and search, you can find one incident or change without opening the database.
When the chain looks partial
The Overview security posture shows whether the audit chain verified. The Audit Log screen does not calculate a chain state; there you compare the current and previous hash of adjacent events by hand. A filter can produce a partial view, so rule that out first. If the warning remains, keep the current state and follow the documented recovery path. Do not hide or rewrite the condition.
- Note the active filters, date range, and chain state
- Find the first inconsistent event and the last good one before it
- Check for a restore, import, update, or retention job in the same window
- If nothing approved explains it, stop non-essential writes
- If the warning persists, write privately to support@vaultpilot.io
- Do not send database files, backups, raw logs, or raw exports
Limits to know
- Audit history covers supported events, not every endpoint or every action in outside systems.
- A healthy chain shows only that the sequence is consistent. It does not show that each action was appropriate, and it is not a compliance document or legal evidence.
- When an investigation reaches beyond VaultPilot, you also need the records of those other systems.
Check step by step
Read more in the guides: Audit and security posture, Audit Log screen guide, Partial audit chain recovery