The two audit trails

Administration and Content Credentials — what is in them and how to find what you are looking for.

Settings → „Audit“ holds two trails, switchable through „Audit-Ansicht wählen“ (Choose audit view):

  • „Verwaltung“ (Administration) — what was changed in the workspace.
  • „Content Credentials“ — signing, verifying and serving files.

Owners and admins only. For everybody else the surface is not reachable.

The signed-in product speaks German, so its labels are quoted in German throughout, with the English rendering in italics.

Entries stay as they are

Both trails are only added to. Updating and deleting are excluded.

An entry is written together with the change it documents. If it fails, the change fails: there is no change without its entry and no delivery without its row.

Rows outlive their subject. Where an output is deleted, folder and file stay empty in the row and the row itself stays readable; the burnt-in label variant sits in the event.

The „Akteur“ and „Veranlasst von“ columns

Where the „Akteur“ (actor) column reads „System“, no human was involved. In the Content Credentials trail that applies to every signature and every verification — the service performs both. In the administration trail „System“ appears for the automatic trash sweep and for an operational intervention.

„Veranlasst von“ (originated by) does not name who triggered the event but who created its subject: who produced the output or uploaded the file. A signature therefore never has an actor but always has an originator.

Where „Veranlasst von“ is empty, either nothing was recorded or the output was deleted. Empty fields cannot be filtered for.

What you can filter

The administration trail has three filters — event, actor and a free-text search — plus sorting; the Content Credentials trail has five.

The free-text search „In Details suchen …“ (search in details) searches the details column and the subject's identifier, not the event name.

Neither trail has a time filter. To narrow a period, use the export.

When an event is not in the picker

Eight events are written by the trail without appearing in the event picker:

  • the change to third-party usage rights
  • calibrating a label variant
  • the five events around domain verification
  • and one more

In the table they appear under their technical name. Seven of them leave the details column empty; for revoking a domain verification a technical word stands there.

Two routes reach them anyway:

Sorting. The „Ereignis“ (event) column is sortable and sorts by the technical name. The eight then stand together.

Exporting. The spreadsheet has a column of its own, „Aktionsschlüssel“ (action key), carrying the technical name. A spreadsheet filter reaches all eight.

When an event does not appear at all

From the member area only two events write an entry: „Einladung erstellt“ (invitation created) and „Einladung widerrufen“ (invitation revoked). Role change, deactivation, removal and accepting an invitation do not appear in the trail.

Where a person has been removed from the workspace, they are no longer in the actor picker either — they cannot be filtered for after that.