# Security and audit information

## Security and audit information

The audit trail is the activity list that records who did what, when, for the project you
select. Use this page when you need to review project activity or export the activity list.
Who did what, when — the full audit trail for the selected project.

| If you need to… | Go to |
| --- | --- |
| Choose the project whose activity you need to review | [Before you start](#before-you-start) |
| Reach the audit page | [Open the audit surface](#open-the-audit-surface) |
| Identify filters, columns, and export controls | [Understand the audit screen](#understand-the-audit-screen) |
| Filter, inspect, page through, or export events | [Review and export audit information](#review-and-export-audit-information) |
| Interpret an empty or changing result | [Handle empty and changing audit results](#handle-empty-and-changing-audit-results) |
| Review the broader security and audit surfaces | [Security & Audit overview](doc:security-and-audit-overview) |
| Review related audit information | [Audit reference](doc:audit-reference) |

## Before you start

Select one project before reviewing its audit trail. This page is intended for administrators.

**Prerequisites**

- Know which project you need to review.
- Have access to the administrator area.

**Steps**

1. In the header dropdown, select the project whose activity you need to review.

   If no project is selected, the page displays the title `Select a project`, the hint
   `The audit trail is scoped to one project at a time.`, and the instruction
   `Choose a project from the header dropdown to view its audit log.`

**Result:** The audit page is ready to show activity for the selected project.

## Open the audit surface

The Security & Audit page is the administrator entry point for reviewing activity for a
selected project.

**Prerequisites**

- Know which project you need to review.

**Steps**

1. Open the Security & Audit page.

**Result:** The `Security & Audit` page opens.

## Understand the audit screen

The audit screen combines an action filter, an event table, pagination, and a CSV export
control.

| Area | What you use it for |
| --- | --- |
| **Action filter** | Narrow the activity list to one action option. |
| **When** | See when an event occurred. |
| **User** | See which user is associated with an event. |
| **Action** | See the action recorded for an event. |
| **Details** | Read the event description. |
| `Showing <start>–<end> of <total> events` | See the current result range and total. |
| **Previous** and **Next** | Move between result pages when those controls are available. |
| **Export CSV** | Request a CSV copy of the audit information. |

The **Action filter** is available after a project is selected. Its options are:

| Option | Use |
| --- | --- |
| `All Actions` | Show all available actions. |
| `version.published` | Filter for version-published events. |
| `document.updated` | Filter for document-updated events. |
| `document.edited` | Filter for document-edited events. |
| `webhook.received` | Filter for webhook-received events. |
| `version.reviewed` | Filter for version-reviewed events. |
| `export.downloaded` | Filter for export-downloaded events. |
| `schedule.triggered` | Filter for schedule-triggered events. |

## Review and export audit information

Use this procedure to narrow the activity list, inspect an event, move through the results,
or request a CSV export.

**Prerequisites**

- A project is selected.
- Audit events are available for the project when you need to inspect a row or use pagination.

**Steps**

1. In **Action filter**, select the option that matches the activity you need to review.

   Use the following options:

   | If you need to review… | Select |
   | --- | --- |
   | Every available action | `All Actions` |
   | A published version | `version.published` |
   | An updated document | `document.updated` |
   | An edited document | `document.edited` |
   | A received webhook | `webhook.received` |
   | A reviewed version | `version.reviewed` |
   | A downloaded export | `export.downloaded` |
   | A triggered schedule | `schedule.triggered` |

2. When `Loading audit events…` appears, wait for the audit list to finish loading.

3. Select the audit row you want to inspect.

   The row expands to show its metadata.

4. Select **Previous** or **Next**:

   | If you need to… | Select |
   | --- | --- |
   | Return to preceding events | **Previous** |
   | Continue to later events | **Next** |

5. Select **Export CSV** to request a CSV copy of the audit information.

   While the request is being prepared, the control displays `Exporting…`.

**Result:** The page shows the selected activity, expanded metadata, another result page, or
the exporting state, depending on the action you took.

## Handle empty and changing audit results

The audit page changes its content when the project selection, loading state, event count, or
result position changes.

| What you see | What it means |
| --- | --- |
| `Select a project` | No project is selected. |
| `Loading audit events…` | The page is loading the audit list. |
| `No audit events found` | The selected project has no events in the current result. |
| **Previous** | Earlier results are available. |
| **Next** | More results remain after the current page. |

**Prerequisites**

- You have opened the audit page.

**Steps**

1. Read the message displayed in the audit content area.
2. Follow the action for the message you see:

   | If you see… | Do this |
   | --- | --- |
   | `Select a project` | Select a project from the header dropdown. |
   | `Loading audit events…` | When Loading audit events… appears, wait for the audit list to finish loading. |
   | `No audit events found` | Read `Events appear here as soon as anything is published, edited, or exported.` |
   | **Previous** | Select **Previous** to return to earlier results. |
   | **Next** | Select **Next** to continue to later results. |

**Result:** The page displays the project audit list, the current empty state, or the result
page you selected.

## When the audit query fails

If the audit query fails, the page clears the event list and total without displaying an
error message.

| What you see | What it means | What to do |
| --- | --- | --- |
| The event list is empty and no error text appears | The audit query returned no usable event list. | Check the selected project and retry the review. |
| No validation, confirmation, or error message appears | No validation, confirmation, or error message appears for this outcome. | Continue with the information displayed on the page. |

**Result:** The page remains on the audit surface with no event list or total displayed.

## Continue from audit review

After reviewing the selected project's audit trail, continue with the related security or
audit material that matches your next question.

| If you need to… | Go to |
| --- | --- |
| Review the broader security and audit surfaces | [Security & Audit overview](doc:security-and-audit-overview) |
| Review related audit information | [Audit reference](doc:audit-reference) |
| Review security information as a task | [Review security information](doc:review-security-information) |

**Result:** You have the audit information for the selected project and a related page for
the next review task.
