Audit log #
Reserved for administratorsObjective and access #
Settings → Audit Log presents sensitive tenant-aware mutations: author, resource, date, IP, correlation and redacted data.
Usage #
Filter events, examine the health chain then export for review. Password or token fields appear as [REDACTED]. The log is append-only and chained by fingerprints.
Business audit #
The Program & CAPA tab belongs to business audit management; the technical log is not a register of findings. See Audits and CAPA.
The screen has exactly two tabs: Program & CAPA and Log technical. There is no separate “Audits” entry in the menu main: business audit functions are located here.
Read and search #
Start with timestamps and correlation, then identify author, organization, action, and resource. Filter by period and context when available. The redacted data explains the operation without exposing the secrets.
Integrity and export #
The integrity action verifies the fingerprint chain. A break must be treated as an incident: preserve database and logs, limit writes and identify the first event concerned. Protect exports, which contain security metadata.
Use cases and limits #
The log allows you to confirm a role change, revocation or API mutation. It does not replace Nginx/PHP logs, nor a SIEM, nor the business audit program. Set retention, backup and access according to your policy.