Lesson 4 of 8 · 9 min

Using the audit log

Find out who did what, and when, to respond to an inspection or an incident.

ObjectiveBy the end of this lesson, you will be able to find out in the audit log who did what and when, and turn it into a documented monthly review.

The audit log records the organisation’s administration and security events. It answers the question that always comes up after the fact: who did what, and when? It is your first source during an internal audit, a question from the data protection officer or an incident.

What you look for in it

  • An account’s sign-ins and failed sign-ins.
  • Members added and removed, and role changes.
  • Changes to the console: assistants, skills, tools, restrictions.
  • Changes to the authentication configuration.

Approvals, on the user side

The audit log covers administration. Decisions taken in day-to-day work are read elsewhere: each user’s “Activity” screen keeps what each task produced, its effects and the history of approvals. During an investigation, the two sources complement each other.

  1. Open the audit log from the organisation’s administration.
  2. Narrow the view to the period concerned.
  3. Then narrow it to the account or event type you are looking for.
  4. Note the relevant events with their date and author.
  5. Attach this extract to the incident or inspection file.

A routine rather than an emergency

Do not wait for an incident to open the log. A fifteen-minute monthly review is often enough: unexpected role changes, settings changed outside the procedure, repeated failed sign-ins on the same account. Anything surprising deserves a question to the person concerned before you draw any conclusion.

Try it in LearnyaHere is the audit log extract for September. Sort the events by type, flag changes to roles and restrictions, and list those that should be checked with the person concerned. Try in Learnya

Keep review extracts in a Drive folder reserved for administrators. During an inspection, you will then show not only the log but also proof that it is read regularly.