# Audit reference

Use the audit views to review recorded activity for one project or across your organization.

## Overview

Audit information records activity associated with a project or organization, including when an
action occurred, who performed it, what action was recorded, and the related entity details.
Use the project view when you are reviewing one selected project's activity. Use the organization
view when you need to review activity across projects.

| If you need to… | Go to |
| --- | --- |
| Review activity for one selected project | [Security and audit access](doc:security-and-audit-access) |
| Review activity across the organization | [Organization audit](doc:organization-audit) |
| Understand empty, loading, or access states | Handle empty, loading, and access states |
| Read the broader security and audit guidance | [Security and audit overview](doc:security-and-audit-overview) |

## Before you start

**Prerequisites**

- Have a project selected before opening the project audit view.
- Use an administrator or maintainer account for the organization audit view.
- Know whether you need project-scoped activity or activity across all projects.

The project view requests events for the selected project. The organization view loads its project
list and event results as you open the page and change filters.

## Find an audit record

An audit record is an entry describing a recorded action, its time, its actor, its entity, and any
available details. Use the project view for one project or the organization view for activity
across projects.

**Prerequisites**

- Have the project selection or account access required by the view you chose.

**Steps**

1. Choose the view that matches the activity you need:

   | If you need to… | Open |
   | --- | --- |
   | Review one project's activity | Project audit view |
   | Review activity across the organization | Organization audit view |

2. Select an event row in the audit table.

**Result:** The selected audit view is open, and an available event row can be inspected.

## Review project audit activity

Project audit activity is the recorded history for the project selected in the application
header. The table presents the time, user, action, and details for each event.

**Prerequisites**

- Select a project before opening the project audit view.

**Steps**

1. Open the project audit view.
2. Select **All Actions**.
3. Choose the action you want to review.
4. Read the event row under **When**, **User**, **Action**, and **Details**.

   ![Use the table headers to identify when the event occurred, who performed it, what action was recorded, and where its details appear.](https://atloriaassets.blob.core.windows.net/assets/a438221c-c1af-407c-b9e6-a56c986db846/fca300b8cc2317d640f36c9f7a7bbc8a.png)

5. Select the event row to expand its details.
6. Select **Export CSV** to download the project audit data.

**Result:** The project audit table is filtered or inspected, and the project audit data is ready
to download as CSV. Continue with organization audit activity when you need a cross-project view.

## Review organization audit activity

Organization audit activity is the recorded history across the organization. Use its filters to
narrow results by action, actor, project, or date, then inspect the matching event details.

**Prerequisites**

- Use an administrator or maintainer account.

**Steps**

1. Open the organization audit view.
2. Select **All Actions**.
3. Choose an action.
4. Select **All Actors**.
5. Choose an actor.
6. Select **All Projects**.
7. Choose a project.
8. Enter a start date in **Start date**.
9. Enter an end date in **End date**.
10. Select an event row to expand its event details.
11. Move through the result pages:

   | If you need to… | Select |
   | --- | --- |
   | Open the earlier result page | **Previous** |
   | Open the later result page | **Next** |
12. Choose the export format:

    | If you need to… | Select |
    | --- | --- |
    | Export comma-separated data | **Export CSV** |
    | Export structured data | **Export JSON** |

**Result:** The organization audit table shows the filtered activity, the selected event's details,
or the next available result page; the organization data can also be exported in CSV or JSON form.
If a state message appears, identify it in Handle empty, loading, and access states.

## Handle empty, loading, and access states

The audit screens show a distinct message while data loads, when there are no matching events, or
when the organization request is refused. Use the message on screen to identify the state before
continuing.

| What appears | What it means | What to do |
| --- | --- | --- |
| `Select a project` | No project is selected for the project audit view. | Select a project from the application header. |
| `The audit trail is scoped to one project at a time.` | The project audit view covers the selected project. | Continue in the project audit view. |
| `Loading audit events…` | The project audit events are loading. | Wait for the event list to finish loading. |
| `No audit events found` | The project event list is empty. | Review the selected project or change the action filter. |
| `Events appear here as soon as anything is published, edited, or exported.` | The project audit list has no events yet. | Continue in the project audit view after an event is recorded. |
| `Loading...` | The organization event table is loading. | Wait for the organization results to finish loading. |
| `Only admins and maintainers can view the organization audit log.` | The organization audit request returned a permission error. | Open the page with an administrator or maintainer account. |
| `Could not load the audit log.` | The organization audit request failed for another reason. | Use the organization audit page again when the request can be loaded. |
| `Export failed` | The organization export did not complete. | Return to the organization audit view. |
| `No audit events` | The organization table has no rows. | Change the organization filters. |

When organization results exist, the page shows a result range and pagination. **Previous** is
disabled on the first page, and **Next** is disabled on the last page.

**Result:** You can identify whether the page is waiting for results, has no matching events, or
requires a permitted account before continuing to the related audit task.

## Continue from an audit record

After reviewing an audit record, continue with the page that matches the work you need to do.

- For project-scoped access and the project audit entry path, open [Security and audit access](doc:security-and-audit-access).
- For organization-wide audit administration, open [Organization audit](doc:organization-audit).
- For broader security context, open [Security and audit overview](doc:security-and-audit-overview).

The project and organization audit views are separate screens. After inspecting event details or
exporting data, open the related access, organization, or security guidance.

**Result:** You know which related page to open for focused access, organization, or security
guidance.
