Skip to main content
Staff only

What the staff audit trail covers

Audit Logs, in the Available Apps panel, opens the platform audit trail. This page is the reference for its scope and event names.

What you'll need
  • The Audit Logs module visible in your left-hand navigation.
  • A staff sign-in. Audit logs are available to staff users only; a non-staff session is refused.

If Audit Logs isn't in your navigation, your role doesn't have visibility for it — ask a workspace administrator, or see Permissions and module visibility.

Whose events you see

One tenant and one service, at a time — the trail is kept per tenant and per source service. Until you choose both, the page reads Choose a tenant to begin and nothing is fetched.

A staff session may read any tenant's trail, but only the one chosen in Select tenant. There is no cross-tenant view and no tenant column. Every search, and every event you open, is itself recorded against the tenant you inspected.

The tenant and service dropdowns

Neither offers Any. Select tenant lists each tenant's name with its identifier beneath it; Select service lists a readable label with the platform's internal name for that service beneath, so a service you know by that name is still findable.

The service is pre-chosen: the page arrives on IntELIEDocs, and clearing it returns there rather than leaving it empty. The tenant is not. Clear filters keeps both — they are the question, not a filter on it.

The five pipeline workers

Workflow engine, Text extraction (Lens), Classification, Field extraction and Document normalization report the processing pipeline itself. They share one vocabulary, so which work a row describes comes from the service you selected and the stage value under Details, not from the event name. These five are far higher volume than IntELIEDocs, Documents and Audit (its own reads), and their Chain position and Chain hash read : they publish directly, so a missing row means telemetry was lost, not that the work did not happen.

Event names

Every event shows a readable sentence with its raw name beneath. Select the chevron inside Event type (e.g. document_) for the full list; matching is by prefix, so a family prefix returns the whole group.

PrefixWhat it returns
document_Every document journey event
file_Every file lifecycle event
smart_extract_Every extractor event
smart_class_Every classifier event
smart_queue_Every queue event

The pipeline workers share one set instead: task_started reads Processing step started, task_failed reads Processing step failed. The set is not fixed — each service decides what it records, and an unfamiliar name is still shown, spelled out from the name itself.

Next

Steps verified against elie-staff-ui @ origin/dev 2026-08-04 on . Something wrong with this page?