Skip to main content
Staff only

Searching the staff audit trail

The staff console searches the platform audit trail one tenant and one service at a time — both are required, because the trail is stored that way.

What you'll need
  • The Audit Logs module visible in your left-hand navigation.
  • A staff sign-in — a separate address and session from the tenant app.

If Audit Logs isn't in your navigation, your role doesn't have visibility for it — ask a workspace administrator, or see Permissions and module visibility.

Steps

  1. Select the button at the far left of the top bar, then the Audit Logs tile — Search the platform audit trail — in the Available Apps panel.

  2. Pick a tenant in Select tenant — until you do, the page reads Choose a tenant to begin — then set Select service, which arrives on IntELIEDocs.

  3. Add filters from the bar, or type a prefix such as document_ into Event type (e.g. document_) to pull one family of events.

  4. Select View details on a row to open it in a side panel.

The filter bar

ControlChoices
Select tenantThe tenant name over its raw id. No Any.
Select serviceIntELIEDocs, Documents, Audit (its own reads), Workflow engine, Text extraction (Lens), Classification, Field extraction, Document normalization — each over its raw service name. No Any.
SeverityAny, CRITICAL, HIGH, MEDIUM, LOW, INFO
CategoryAny, Security, Privileged operation, Configuration change, Data access, Authentication, Lifecycle
OutcomeAny, SUCCESS, DENIED, ERROR
StatusAny, COMPLETED, IN_PROGRESS, PENDING, FAILED, CANCELLED
Any timeAny, Last 24 hours, Last 7 days, Last 30 days, Custom range
Event type (e.g. document_)A prefix, matched case-insensitively; the chevron in the box lists five family prefixes and every known type.
Actor IDFree text — a user, staff or service identity.

Event type and Actor ID are the only free-text fields. Presets resolve when the search runs, so Last 24 hours always means the last 24 hours from now; Custom range adds a calendar and includes both end dates. Set filters are highlighted and counted on Clear filters (3), which drops them all but keeps the tenant and service.

The results table

Columns are When, Action, Severity, Category, Actor, Resource and OutcomeAction shows the readable sentence over the raw event token, When local time with the exact instant on hover. Columns do not sort: order with Newest first / Oldest first. Rows per page (10, 20, 50 or 100) and Showing 20 from 1,234 events sit above the table. A first search reads Loading…; later changes keep the previous rows while the Refresh icon spins, and nothing reloads on its own.

What success looks like

  • Five tiles — CRITICAL, HIGH, MEDIUM, LOW, INFO — appear above 1,234 event(s) recorded for this service: the whole tenant-and-service trail, not your filtered view. Selecting a tile filters by that severity; selecting it again clears it.
  • Matching rows fill the table, and View details opens one event.

Tenant, service, every filter, the page, the order and the open event all live in the address — bookmark it to return to this search, or send it to a colleague and they see your exact view. Changing the question returns you to page 1.

If something goes wrong

SymptomLikely causeWhat to do
Choose a tenant to beginNo tenant picked.Pick one in Select tenant.
Select tenant opens with no rows.The tenant list failed to load.Reload the page.
No events found.The filters exclude everything, or that pair holds nothing.Widen Any time, or select Clear filters.
Could not load the audit trail. Check the filters and try again.The search was refused, or the service is unreachable.Adjust the filters, then Refresh.
The service returns to IntELIEDocs.Clearing it re-applies the default.Choose the service you want outright.

Next

Steps verified against elie-staff-ui @ origin/dev 2026-08-04 on . Something wrong with this page?