Overview
The audit log captures administrator actions, employee sign-ins, automated system actions, and configuration changes across every product module. You can review entries in the Right-Hand Cybersecurity portal, or retrieve them through a read-only API and send them to your SIEM or other monitoring tool.
Use the audit log as your authoritative record when you investigate administrative changes, authentication events, integration activity, data exports, and privacy operations.
Who can access the audit log?
Company administrators: Only administrators who have the audit-log permission can view the audit log. Other users are refused access.
MSSP partners: MSSP partners can access their customers' audit logs through the partner API.
You can access the Audit Logs on the portal using the path below:
Settings > Audit Logs tab.
What each entry contains?
Field | Description |
Actor | The administrator, employee, Right-Hand Cybersecurity support user, or system process that performed the action. |
Action | What happened, in plain language, such as "Employee archived." |
Target | The record affected, such as an employee, integration, report, or setting. |
Channel | How the action was performed, such as the portal, CSV import, SCIM, an SSO provider, the API, or an automated process. |
Timestamp | When the action occurred. |
Details | Additional context, such as a failure reason, report type, or the fields that changed. |
What the audit log records?
Sign-ins and sessions
Successful sign-ins using password, email OTP, mobile OTP, Google SSO, Microsoft SSO, SAML SSO, magic links, and training access links.
Failed sign-ins using the same methods, with the reason - for example, wrong password, locked account, wrong OTP, OTP lockout, expired or already-used link, SSO account not found, or SSO assertion failure.
Explicit sign-outs and session expiry.
Access-denied events.
Sign-in link resends, including resends blocked by CAPTCHA, cooldown, or access rules.
Right-Hand Cybersecurity support sessions, including when our support staff access your account on your behalf.
Employees and organization structure
Employee creation, updates, archiving, restoration, and deletion, including bulk actions.
The source of each change: portal, CSV import, SCIM, Entra ID, Google Workspace, or on-premises Active Directory.
Changes to departments, divisions, office locations, titles, employee types, and user groups.
Employee invitations and file imports.
Roles and access control
Role changes for administrator, manager, and custom roles, whether made through the employee form, bulk assignment, people-manager assignment, CSV import, or automated assignment.
Changes to role definitions.
SSO, provisioning, and directory sync
SAML SSO connections that are connected, enabled, disabled, automatically disabled, updated, or disconnected.
Azure Entra ID connections that are connected, updated, or disconnected.
SCIM enablement, disablement, and token regeneration.
Company email domains (root domains and subdomains) that are added, verified, failed, expired, or deleted.
Active Directory connections, imports, and directory-sync history.
Security tool connectors
Connector connections, whether made by an administrator or automatically when the first data arrives.
Connector configuration changes and disconnections.
Automatic connector disablement after repeated failures.
Webhook token generation for webhook-based sources such as Splunk, Cloudflare, and Zscaler.
Human risk management
Changes to human-risk alerts, including severity, type, and enablement.
Company risk-score recalculations, whether requested manually or triggered by the system.
Changes to risk-score configuration.
Access to automation execution history.
Employee notifications
Bulk notifications for employee kickoff, Ally kickoff, campaign reminders, training reminders, pending-training reminders, and PhishArm guides.
Awareness poster distribution.
Changes to notification and email templates.
Reports and data exports
Every export is recorded with its report type, including:
Company dashboards by department, division, location, and user group.
Phishing reports covering attacker profiles, email templates, and repeat offenders.
Training reports covering targeted trainings, feedback, users, SCORM packages, and training content.
Campaign reports, employee lists, employee activity, manager analytics, pending trainings, competition results, survey dashboards, executive PDF reports, posters, and PhishArm manifests.
Data deletion and privacy requests
Permanent employee deletions and privacy requests.
PhishArm and email quarantine
EQA configuration changes and Microsoft 365 or Google Workspace connection changes.
EQA searches, query results, and remediation actions.
Reported emails and their status changes.
Blocklist history.
Phishing-alert settings.
Phishing simulations
Creation, updates, and deletion of campaigns, email templates, landing pages, attacker profiles, brand identities, and competitions.
Training and Ally
Creation, updates, and deletion of trainings, courses, slides, quizzes, and templates.
Ally configuration changes.
Company and security settings
Company profile changes.
Security setting changes.
SMTP setting changes.
API token changes.
Search and filter audit log entries
You can search audit log entries and filter them by category and date range to narrow down the activity you're investigating.
Send audit log entries to your SIEM
A read-only API returns audit log entries so you can ingest them into your SIEM or other monitoring tool.
Note: You can access the Audit Log API using this link.
Audit log integrity
Audit log entries are read-only. You can't edit or delete entries in the portal or through the API, so the log remains a reliable record of activity in your account.
