Executions screen

Executions combines update jobs, AD agent actions, and selected audit events in one time-ordered view. It is not a task launcher or a general-purpose retry console.

Access, role, and license boundary

Owner, Admin, and Auditor can open Executions. The User role cannot open it. The vault must be unlocked and the session confirmed before the list loads.

Viewing needs no separate license feature, and a read-only license does not hide existing records. Only an Owner sees Stop execution on an eligible AD agent action. Stopping is a change, so a read-only license refuses it. Open source can lead to a screen such as Update Center or Integrations that has its own role and license rules.

What you can do here

  • Narrow the loaded executions by category and state group.
  • Read an execution’s summary, state, progress, source, target, actor, and last update time.
  • When present, inspect steps and the short log summary to find the affected stage.
  • Use Refresh to load the current list; while the view is open it also refreshes automatically every few seconds.
  • Use Open source to move to Update Center, Integrations, or Audit Log.
  • As an Owner, stop only a pending or running AD agent action after confirmation.

There is no general Retry action on this screen. Do not restart an update, Discovery run, maintenance operation, or failed AD action here. Keep and inspect the evidence first, then start a new run only if the source screen offers that action.

Runs and Scheduled tabs

The Tasks workspace has two separate views:

  • Runs shows work that has started or finished and refreshes every few seconds while open.
  • Scheduled shows future policies and work waiting to retry, and refreshes less often while open.

The top-bar refresh reloads only the selected tab. It does not reload the browser page, and filters stay as they are.

Scheduled operations

Scheduled combines Active Directory rotation, directory sync, certificate lifecycle checks, and queued outgoing email. Each card shows its source, trigger, cadence, next run, last run, last outcome, related execution, and a short log summary when available.

Because VaultPilot cannot read certificate contents on the server, certificate lifecycle scanning runs only in an authorized, unlocked browser session. VaultPilot does not invent a last or next run for it. The card can show an hourly cadence that needs a signed-in session; completed expiry warnings come from the audit history.

StateMeaning
ReadyThe policy is enabled and waiting for its next time.
DueWork is waiting to be picked up.
RunningThe related execution is active.
RetryingThe source is waiting before trying again after a failure.
BlockedPermissions, agent health, vault state, or a lasting error prevents progress.
PausedAn operator or the source policy has paused the schedule.

Filters are All, Active, Attention, Ready, and Paused. Cadence can be daily, weekly, monthly, a custom interval, the hourly certificate scan, or the source’s retry interval. A trigger can be Calendar, Secret reveal, or Password age. Open source opens the matching rotation policy, Active Directory provider, Certificates workspace, or email setting without starting a new run.

Data sources and scope

The list shows the most recent entries, newest first:

SourceOn-screen source labelWhat it representsOpen source destination
Update jobUpdate jobLive state, steps, and messages for a server or browser-extension updateUpdate Center
Directory agent actionAD agent actionA pending, running, or finished AD operationIntegrations
Audit eventAudit eventA recorded sharing, security, Discovery, vault, integration, or system actionAudit Log

A live Discovery job does not appear as its own execution. Events such as policy save, scan start, finding suppression, import preparation and completion, and remediation completion appear as Recorded audit entries. Use Discovery for live progress, cancellation, and past runs.

Maintenance actions such as server-settings saves, restarts, and maintenance cleanup can also appear as System audit entries. Execution backup, cleanup, and restore are not done here; use Server settings > Operations. Execution cleanup can remove finished update and directory-action records while keeping active work. Audit entries follow the separate Audit maintenance category, and cleanup records its own audit entry.

Filters

Category and state filters narrow rows together, but the counts on the buttons do not show their overlap. Category counts ignore the selected state, and state counts ignore the selected category.

CategoryContent
AllEvery loaded source.
UpdateLive update jobs and update audit events.
DirectoryLive AD agent actions and selected directory-action audit records.
SharingShare and share-revoke audit events.
SecurityUser, session, 2FA, and Discovery security events.
IntegrationDirectory, integration, and extension audit events.
VaultDelete, export and import, and completed Discovery import events.
SystemMaintenance, restart, license, and other system audit events.
State filterIncluded row states
All statesEvery state.
ActivePending, Running, and Cancel requested while waiting for the agent to confirm.
ProblemFailed, Blocked, and Review.
CompletedSucceeded, Recorded, and Cancelled.

A Cancelled entry appears under Completed only because it is no longer active; it is not a success. If the filtered view is empty, the screen says No executions match this filter. That does not prove there are no records under another filter or older than the entries shown.

Card, step, and log details

Each card shows operation, summary, state, and percentage progress. Its detail row contains source, target, actor, and Updated time. A missing target or actor shows -.

When available, the card shows the first few steps. Each step has a label, a detail or general state, and a percentage. Step states are pending, running, done, blocked, or failed. Further steps are not shown here.

When present, Logs shows the latest few entries. Each has a level (Info, Success, Warning, or Error), message, time, and optional technical detail. Logs open by default for Running, Failed, and Blocked entries; for other states, expand them yourself. This summary is not the full server log or a delivery receipt.

The card does not show an execution ID, start time, or completion time. Do not claim you captured a job ID from this screen when none was visible.

State semantics

Visible stateSource state and interpretation
PendingA queued or ready update job, or a pending AD agent action. Do not assume it is already running on the server or agent.
RunningAn update is running or the AD agent has picked up the action. The percentage alone does not prove progress; check Updated as well.
SucceededAn update completed or an AD agent action reported success. Confirm the intended result on the source screen.
FailedAn AD agent action ended in error. Keep the message and redacted detail; there is no retry here.
BlockedAn update job cannot continue. Inspect its step and log detail, then open Update Center.
Cancel requestedThe stop was recorded but the agent has not yet confirmed it. Treat it as active and wait.
CancelledAn Owner stopped an AD agent action. Execution and audit evidence are kept.
ReviewThe directory action needs review because its result is uncertain. Do not treat it as success or a normal delay; review agent health and the target account.
RecordedAn audit event was saved. This alone does not prove that a related external action finished successfully.

Refresh, stop, and retry

Refresh reloads only the list; it does not start an operation. While loading, the button is disabled and reads Refreshing.

Stop execution appears only for an AD agent action in Pending or Running, and only to an Owner. Confirming first records Cancel requested. The action is not cancelled until the agent confirms and reports a final state. An agent that lost the action cannot write a later result. Finished executions and audit evidence are not deleted; update jobs and audit entries cannot be stopped from Executions.

There is no retry action here. Open source does not rerun anything; it only opens the related screen. A Recorded Discovery or maintenance event is not a control for cancelling or restarting a live job.

Investigate a problem execution

  1. Select Problem, then the relevant category.
  2. Separate Failed, Blocked, and Review before deciding which evidence matters.
  3. Inspect last update time, progress, steps, and the log entries.
  4. Redact actor, target, directory DN, host, path, and error detail before sharing evidence.
  5. Choose Open source and confirm the same work is not still active before starting any new action there.

Stop an active AD agent action

  1. Select Directory and Active.
  2. Confirm target, actor, last update time, and agent health.
  3. Check that the entry is really Pending or Running and that the target is correct.
  4. As an Owner, choose Stop execution and read the confirmation.
  5. After refresh, confirm Cancelled and the matching audit entry.

Screen states

StateOperator response
LoadingPlaceholder rows appear; do not treat the temporary empty view as final.
No executions match this filterBroaden category or state, and check the source screen for older records.
RefreshingDo not start a second refresh; wait for the current one.
List unavailableThere may be no separate error card. Check the session and vault lock, role, and server connection, then refresh; an empty view does not prove that no records exist.
PendingThe work is queued; do not start a duplicate from its source.
RunningWait while Updated advances; if it stops, inspect the source and service or agent health.
FailedKeep redacted error evidence; this screen cannot retry it.
BlockedRead the blocked step and log detail, then open Update Center.
ReviewDo not count the directory action as success; check agent connectivity and the target account.
SucceededConfirm the intended result at the source; 100% alone does not prove the change took effect.
RecordedAn audit event exists; do not assume a live or successful related job.
CancelledThe action is not active; it stays under Completed, and audit evidence is kept.
Stop action absentThe row is not an active directory action or you are not the Owner. Under a read-only license the button can still appear, but the stop is refused.

Before you act

  • Confirm your role and whether the license is writable; permission to view is not permission to stop.
  • Note the active category and state filters; a filtered empty view is not the full history.
  • Check whether Updated is changing and whether the source already has active work.
  • Before stopping, confirm the target and actor; an AD action the agent already picked up may already have changed the target.
  • Keep Recorded separate from the real outcome of update, Discovery, or maintenance work.
  • If maintenance cleanup or restore is planned, keep private evidence and complete the approved backup workflow first.

Safe evidence

  • Safe to share: source and category, visible state, approximate progress, broad time window, redacted operation or step label, log level, and the general error message.
  • Keep private: actor and user name, real target and directory DN, host and domain, local paths, file or package names and locations, full log messages and details, full audit hashes, backup file names, and machine-specific traces.
  • A card title does not make a screenshot safe. Review and mask summary, target, actor, step detail, and each log line.
  • For support, prefer category, state, broad time window, and a redacted error message. Send raw logs or directory targets only when support asks, and only as much as needed.

When to stop and escalate

Stop starting new work if a Running entry no longer updates, the same execution keeps reappearing, the reason for Review is unclear, an update stays Blocked, a stopped AD action still affects its target, or Executions disagrees with the source screen. Email support@vaultpilot.io with the redacted source, category, state, broad time window, last visible step, and general error message.

Operator notes

Executions combines different kinds of work; not every row is the same kind of job. A Recorded audit event, a Succeeded operation, and a Cancelled action are not interchangeable. Steps and logs are shortened; detail missing here may exist elsewhere, so do not fill it in by guesswork.

Back to Documentation