CaryvaneHelp
/

Audit trail

Every action that changes something is recorded with the user, the time and the IP address it came from. It is the answer to "who did that?" and to an auditor's "show me".

Where #

Audit Trail in the console, scoped to the customers you can see. Newest first, with the event, the actor, the customer and a detail line; search narrows it.

What is recorded #

AreaEvents
AccountsSign-up, social sign-up, password change and reset, admin-set password, MFA enabled and reset, user created, updated, deleted
CustomersCustomer created, updated, status changed (suspended, reactivated), cloud credits granted, migrations scheduled and cancelled
AgentsRegistered (by token or by user), reattached, replaced, deactivated, reactivated, enrolled elsewhere; deployment token created and revoked
JobsCreated, updated, deleted, started, cancelled; per-file upload and failure events on runs
StorageTarget created, updated, deleted; archiving switched on/off; archive rule set and removed
Cloud drivesDrive updated (mounted, changed, removed)
Access keysAI key created and revoked; cloud worker keys created and revoked
ConnectorsMicrosoft 365 and Google Workspace archives and restores started
BillingSubscription started and cancelled, payment set-up, auto-pay changed, invoice paid now, trial reuse flagged

Actions taken through an AI access key or the API are attributed to the key's owner, exactly as if they had used the console.

Retention #

Audit events are kept for the life of the account and 90 days after it closes. They are not editable.