Skip to content

Audit Trail

The Audit Trail provides a tamper-resistant, immutable record of every action performed in the SSL-CLM platform — by users, agents, and automated system processes.

Navigation: Sidebar → Governance → Audit Trail

Audit Trail


The main view displays audit entries in reverse chronological order:

ColumnDescription
TimeRelative timestamp (e.g., “3h ago”, “2d ago”) with exact time on hover
ActionEvent type as a color-coded badge
DescriptionHuman-readable detail of what happened
EntityResource type affected (e.g., CERTIFICATE, CA, AGENT)
ActorWho performed the action — username or system identifier

ActionColorMeaning
CREATEDBlueResource was created
ISSUEDGreenCertificate was issued
RENEWEDGreenCertificate was renewed
DEPLOYEDTealCertificate was deployed to a store
REVOKEDOrangeCertificate was revoked
DELETEDRedResource was deleted
REGISTEREDBlueAgent was registered
WENT_OFFLINERedAgent stopped reporting
REJECTEDRedApproval request was rejected
APPROVEDGreenApproval request was approved
CONFIGUREDBlueSettings were changed
DISABLEDGrayResource was disabled
FAILEDRedOperation failed

EntityWhat It Covers
CERTIFICATECertificate lifecycle events (creation, issuance, renewal, revocation, deployment)
CACertificate Authority CRUD, health changes, sync operations
AGENTAgent registration, status changes, job execution
STORECertificate store CRUD, deployment operations
ACME_PROFILEACME server profile creation, modification, deletion
POLICYPolicy CRUD, enable/disable events
USERUser CRUD, role assignments, login events
ROLERole CRUD, permission changes
TEAMTeam CRUD, member changes
DNS_PROVIDERDNS provider CRUD, verification events
JOBJob lifecycle events
SETTINGSSystem setting changes

Each audit entry records who performed the action:

Actor TypeExamplesMeaning
Useradmin@example.com, john.doeHuman user performed the action via UI or API
SystemSystemPlatform automated process (scheduler, auto-renewal)
AgentAGENT:agent-idAgent executed a job
heartbeat-monitorheartbeat-monitorSystem process that detects agent status changes

Free-text search across all fields — description, entity, actor, action.

Dropdown to filter by resource type:

  • All Entities
  • CERTIFICATE
  • CA
  • AGENT
  • STORE
  • ACME_PROFILE
  • POLICY
  • USER
  • (etc.)

Dropdown to filter by event type:

  • All Actions
  • CREATED
  • ISSUED
  • RENEWED
  • DEPLOYED
  • REVOKED
  • DELETED
  • (etc.)

Click the refresh button to load the latest entries.


Click any row to expand its full details:

FieldDescription
Log IDUnique identifier for this audit entry
TimestampExact ISO-8601 timestamp
ActionEvent type
Entity TypeResource type
Entity IDSpecific resource identifier
Actor TypeUSER, SYSTEM, or AGENT
Actor IDUser email, system process name, or agent ID
DescriptionFull human-readable description
DetailsStructured JSON payload with operation-specific data

Certificate Issued:

{
"certificateId": "cert-abc123",
"commonName": "api.example.com",
"caId": "ca-smallstep-1",
"serialNumber": "1A2B3C4D",
"validFrom": "2026-08-20T00:00:00Z",
"validTo": "2027-08-20T00:00:00Z"
}

Agent Went Offline:

{
"agentId": "agent-xyz",
"hostname": "web-server-01",
"lastHeartbeat": "2026-08-20T10:30:00Z",
"offlineSince": "2026-08-20T10:35:00Z"
}

Policy Violated:

{
"policyId": "policy-strict-1",
"policyName": "Production Web Certificates",
"violation": "Key size 1024 below minimum 2048",
"requestedBy": "developer@example.com"
}

Audit logs are:

  • Append-only — Entries cannot be modified or deleted through the UI or API
  • Tamper-resistant — Each entry is stored with integrity metadata
  • Complete — Every state change across the platform is logged
  • Retained indefinitely — No automatic purging (configurable retention in enterprise plans)

RequirementHow Audit Trail Helps
Who issued this certificate?Filter by Entity=CERTIFICATE, Action=ISSUED
When was this CA last synced?Filter by Entity=CA, look for CA_REFRESH events
Who approved this deployment?Filter by Action=APPROVED, Entity=CERTIFICATE
Why did this agent go offline?Filter by Entity=AGENT, Action=WENT_OFFLINE
What settings changed recently?Filter by Entity=SETTINGS, Action=CONFIGURED
Track all user login activityFilter by Entity=USER, Action=AUTHENTICATED

Audit logs can be exported for external analysis or compliance reporting:

  • Navigate to Governance → Reports
  • Generate an Audit Report for a specific date range
  • Export as CSV, PDF, or Excel