Open Audit Trail to review tenant activity. Events include a timestamp, action, actor or system source, resource, outcome, and redacted context.

Filtering and event details

Filter by time, actor, category, action, outcome, resource, and system or user events. Use cursor pagination to move through large histories. Open an event to see its immutable event ID, correlation ID, source service, and safe metadata.

System events do not have a staff or tenant actor. This is expected for scheduled assessments, provider synchronization, queue processing, and delivery workers.

Exports and retention

Export requests are themselves audited. JSON and CSV exports contain only the events in your tenant scope and omit secrets, OAuth tokens, credentials, message bodies, attachments, and sensitive provider payloads. EmDash keeps an operational history for the configured retention window; use a configured Splunk or Microsoft Sentinel destination for durable external retention.

Investigating an event

  1. Start with the timestamp and outcome.
  2. Copy the event ID or correlation ID into your incident notes.
  3. Compare the resource and source service with the related page.
  4. If delivery or synchronization failed, review the integration health page and support guidance.
Privacy: Audit metadata is redacted by design. A missing body, token, attachment, or authorization header is a protection, not an incomplete export.