Audit & Logs

Full audit trail and data lineage

Every search, read, approval, and export is logged end to end. Track events across people, projects, and sources, then export a record you can hand to audit or regulators.

Immutable event log Source→claim lineage Reviewer & policy context Exports & webhooks
Access events (24h)
2,318
Reads, writes & approvals
Sources touched
147
Files, DB tables, drives
Reviewers active
19
Approvals & attestations
Anomalies flagged
3
Out-of-policy attempts blocked

What we log

A single ledger for sensitive actions across the workspace.

Retrievals & reads

Opening files, querying databases, and fetching snippets with full residency and source path.

Writes & exports

Brief exports, evidence packs, JSON audit dumps, and downstream shares.

Approvals & attestations

Reviewer identity, scope, rationale, and the exact content they signed off on.

Policy changes

Updates to residency, roles, limits, connectors, and keys, with before/after context.

Anomalies & blocks

Out-of-scope attempts, throttling, lockouts, and other guardrail events.

Integrations & webhooks

Delivery receipts, signatures, retries, and failure reasons for connected systems.

Timeline (sample)

Walk events in order, grouped by day and scoped to your filters.

2025-06-12
09:14
Approved MSA redlines for Vendor X
09:10
Viewed snippet from “Q2 Policy Update.pdf”
09:09
Opened SharePoint source /Legal/Compliance/Q2…
09:08
Retrieval logged via EU/UK residency route
2025-06-11
17:22
Ran Contract Review on Thread #14
16:59
Set project residency to UK for Atlas
16:31
Exported “Exec Brief v12” with anchors

Retention, exports & integrations

Control how long you keep events, how you export them, and where the log stream lands.

Retention policies

Define retention windows by workspace or project. Enforce residency and legal holds with immutable markers.

  • Time-boxed retention and deletion policies
  • Residency-aware routing and holds

Export formats

Export an evidence pack, a brief with anchors, or structured JSON using the same IDs as the live ledger.

  • Evidence pack (PDF)
  • Brief (DOCX/PDF) with anchors
  • Audit JSON for downstream systems

Webhooks & SIEM

Stream events to your SIEM with signed payloads, retries, and flexible schemas per destination.

  • Signed payloads & replay protection
  • Splunk / Datadog / Chronicle integrations

See the full audit story on your data

Filter live events, follow lineage from claim to source, and export an audit-ready evidence pack.

“If you can’t trace it, you can’t trust it. Xybern keeps the entire path visible.”