What audit logs does CueCrux provide?

Explainer

What audit logs does CueCrux provide?

Comprehensive activity logging for compliance and governance

CueCrux maintains comprehensive audit logs that record every significant action taken on the platform. These logs are essential for organisations that need to demonstrate compliance with regulatory requirements, conduct internal investigations, or simply maintain good governance over their information practices.

The audit log captures a wide range of events. Authentication events include successful logins, failed login attempts, session starts, session expirations, and logouts. These records include the user identity, the authentication method used, the IP address, the device fingerprint, and the timestamp. For organisations using SSO, the identity provider's authentication response is also logged.

Document events include uploads, downloads, views, modifications, version updates, and deletions. Each document event records which user performed the action, which document was affected, the workspace context, and the timestamp. For uploads, the log includes the file type, size, and the ingestion result including any quality issues detected. For version updates, the log records the relationship between the old and new versions.

Search events include every query run on the platform. The log records the query text, the search mode used, the filters applied, the number and identity of sources consulted, the answer generated, and which receipts were produced. This level of search logging is unusual among search tools, but it is critical for compliance use cases where organisations need to demonstrate that they conducted appropriate due diligence.

Sharing events record every instance of an answer being shared, whether within a workspace, to another workspace, or externally via a proof link. The log includes who shared, what was shared, with whom, and under what access settings. For external shares, the log also records when the proof link was accessed and by whom if the recipient was authenticated.

Administrative events cover member management, role changes, workspace creation and deletion, policy changes, integration configuration, and billing modifications. Every change to the organisational or workspace configuration is logged with full before-and-after state, so you can reconstruct what the settings were at any point in time.

The audit logs are tamper-evident. Each log entry is cryptographically chained to the previous entry, similar to how blockchain works but without the overhead of a distributed ledger. If anyone attempted to modify or delete a log entry, the chain would be broken and the tampering would be detectable. This tamper evidence is important for organisations that need to present audit logs to regulators or in legal proceedings, because it provides assurance that the logs have not been altered.

Log access is controlled by the audit permission within the role system. Typically, only workspace owners, administrators, and designated compliance roles can access the audit logs. The logs themselves are subject to access logging, so you can see who accessed the audit trail and when. This prevents situations where someone with audit access could review logs without accountability.

CueCrux provides several ways to work with audit logs. The in-app log viewer provides a searchable, filterable interface for browsing log entries. You can filter by event type, user, workspace, date range, and other criteria. The export function lets you download log data in CSV, JSON, or PDF format for offline analysis or archival. The SIEM integration pushes log events in real time to your security information and event management platform, such as Splunk, Sentinel, or Elastic Security, for centralised security monitoring.

Retention policies for audit logs are configurable at the organisational level. By default, logs are retained for seven years, which meets or exceeds the retention requirements of most regulatory frameworks. You can extend or reduce the retention period based on your specific requirements, though some minimum retention periods may be required for certain types of events.

For organisations subject to specific regulatory frameworks, CueCrux provides pre-built audit report templates. There are templates for SOC 2 audit support, GDPR data access reporting, HIPAA access logging, financial services compliance, and general information governance. These templates extract the relevant log entries and format them in the structure expected by the respective regulatory framework.

The audit log system is not an afterthought bolted onto the platform. It is integral to CueCrux's architecture. The same provenance and traceability principles that apply to receipts apply to the audit trail. Every action has a record, every record has a proof, and every proof is verifiable. This comprehensive logging is what makes CueCrux suitable for the most demanding compliance environments.