Reading the audit log requires the Auditor, Admin or Owner role. Auditor
exists specifically for this: it grants read access to the audit log and
cannot change anything at all, which is exactly what a compliance
reviewer should hold. See Roles and permissions.
What is recorded
Each entry carries the actor, the action, the resource type and identifier, and
the time.
Support access is in your log
When aiAxonIQ support is granted time-limited access to your organization
to investigate a ticket, that appears here — who, when, and for how long.It is deliberately in your audit log rather than only in an internal one.
An access record you cannot read is a policy; one you can read is a control.
Filtering
Filter by action type and by resource type, both of which are enumerable — so you can see what kinds of events exist rather than guessing at strings. An individual entry can be opened for its full detail. The common questions:- Who revoked that key? Filter to credential actions.
- What changed before this alert started misfiring? Filter to the rule’s resource type around the time it began.
- Who has been added to this organization this quarter? Filter to membership.
Export
The log can be exported for a compliance review or to keep alongside your own records.What is not here
Detections about your systems — authentication failures, exposed secrets, runtime threats — are security events, which is a different surface. During an investigation you usually want both.Next
Roles and permissions
The Auditor role, and who may grant it.
Security events
Detections over your telemetry.
Organizations
Where the real access boundary is.