The Audit Log shows each event’s actor, affected target, role, timestamp, operation details, and integrity hashes.
Operations > Audit log is shown only to Owner, Admin, and Auditor. Hiding the menu item is not the access control; the server checks the role on every request. The screen does not modify existing events. CSV and Excel exports contain the raw events allowed by the current filters.
What you can do here
- Narrow the list with category buttons, the Action type selector, and Search audit.
- Check the raw event count, selected category, and action type before exporting. The search term is not shown in this summary.
- Open a row to review actor, target, role, time, operation details, the current event hash, and the previous hash together.
- Use Clear filters to return to the full view; CSV and Excel export only the visible result set.
- An
Nxmarker means events with the same action, actor, and target in the same minute are grouped into one display row.
How to read the screen
Category buttons group events; each count is the number of raw events in that category. Action type isolates one operation. Search matches action label, actor, target, narrative, details, timestamp, hashes, and target ID. There are no separate actor, target, risk, or time filter controls.
Events sharing action, actor, target, and minute are grouped into one representative row with an Nx marker. Opening that row shows only the representative event, not every member. Category counts, the result summary, and exports continue to use ungrouped raw events.
The detail drawer shows actor, target, role, time, operation metadata, current hash, and previous hash. These are fields for manual comparison; the screen does not calculate or display a complete, partial, or invalid chain state. For critical changes, open adjacent events and compare their order and hash linkage manually.
Investigation workflows
Find one operational change
- Establish the approximate time and likely actor or target.
- Select a category, then choose Action type.
- Use Search audit for the final narrowing step.
- Open the row and confirm that actor, target, role, and timestamp fit the expected operation.
If nothing appears, do not conclude that logging failed. Choose Clear filters, check spelling and time-zone assumptions, then search again.
Compare event hashes manually
- Open the relevant event detail.
- Preserve both the current event hash and the previous hash.
- If the row is marked
Nx, note that the drawer represents only one event from the group. - Use search and export to compare adjacent raw events in the same time window.
Hashes on this screen do not mean the application has validated the chain. If the previous hash is absent, unexpected, or appears not to match the adjacent raw event, keep records unchanged and email support@vaultpilot.io with a narrow time window and redacted context.
Export a tightly scoped evidence set
- Reduce category, action type, and search term to the smallest useful scope.
- Record raw event count, category, and action type; record the search term separately.
- Choose CSV or the Excel-compatible table according to the fields required.
- Store the filters in a separate investigation note because the file does not describe its own filter scope.
- Keep the original private and immutable; redact user, object, IP, and customer context in the shareable copy.
CSV includes created_at, action, actor, target, summary, details, target_id, integrity_hash, and previous_hash. The Excel button does not create .xlsx; it creates an Excel-compatible HTML table with a .xls extension. That table contains Created, Action, Actor, Target, Summary, Details, and Integrity hash, but omits target_id and previous_hash.
When the filtered raw event count is zero, both export buttons are disabled and no empty file is created. After a download, VaultPilot tries to record the export in the audit history and refreshes the list. The entry is recorded only if the server accepts it. For example, an Auditor can download the file, but the export entry may be missing because the Auditor role cannot create audit entries. Even when recorded, the new event is not present in the file prepared before it.
Hold a safe position during an active incident
For suspected unauthorized access, an unexplained role change, or unexpected hash linkage, pause non-essential administrative changes. Preserve the time window, actual filter scope, and relevant hashes, then hand the case to the incident owner. Do not run cleanup or alter retention while review is active.
Screen states and operational conditions
| State | Operator response |
|---|---|
| Loading | Wait for the list to load before changing filters. |
| No filtered results | Clear filters, then re-check time and search text. |
Grouped Nx row | Remember that the drawer shows a representative event while counts and exports use raw events. |
| Export disabled | The filtered raw event count is zero; review the filters. |
| Export completed | Keep a separate scope note; the export entry appears only if the server accepts it. |
Before you act
- Set category, action type, and search term before exporting; there are no separate actor, target, or time filters.
- Account for
Nxgrouping when manually comparing hashes and adjacent raw events. - Stop non-essential changes if hash linkage is unclear and an active incident is underway.
- Decide the secure storage location and intended recipients before exporting.
- Coordinate cleanup or retention work with the evidence owner before it affects raw history.
- Record search term, time-zone assumption, category, and action type in a scope note separate from the file.
Safe evidence
- Safe to share: event category, narrow time window, redacted actor role, a short hash prefix, and the actual filter scope.
- Keep private: usernames, object IDs, raw audit exports, internal IPs and incident material with customer context.
- If a previous hash is missing or unexpected, preserve evidence and state clearly that this screen does not produce a visible chain-health result.
- Keep category, action type, search term, and raw event count in the shareable copy because the export is not self-describing.
- Never send raw CSV/Excel, detail-drawer metadata, or customer context outside the investigation.
When to stop and escalate
Stop administrative changes when hashes cannot be reconciled with adjacent raw events, actor or target cannot be reconciled, exports omit expected events, or an active security incident is underway. Email support@vaultpilot.io with category, action type, search term, narrow time range, redacted actor role, and event hashes—never raw customer data.
Operator notes
Audit evidence can expose usernames, internal object IDs and operational timing. Redact them before emailing support@vaultpilot.io.