Skip to content
Kanonik
Menu
Help
Browse Help
On this page

Reading your audit log

How to read the Audit log, search and filter it, check the chain in your browser, and see what one person did.

Choose Audit in the left-hand menu to open the Audit log. It lists the decisions people made on your workspace, newest first: what was approved onto the record, sent back or rejected, and by whom. Drafts your AI proposed and the safety check's verdicts are not rows of their own; a verdict shows inside the decision it belongs to. A few kinds of record, such as saved answers, have no row here; you find those in the Workspace. Everyone in the workspace can open it, auditors included.

Entries are never edited or deleted. Each one points at the entry before it, and the chain root is signed, so a changed, reordered or removed entry shows up as a break. An audit trail that survives scrutiny explains why that matters to an auditor.

When to open it

Open it when:

  • someone asks who approved a policy or a control, and when,
  • you want to see what one person decided, or what was sent back or rejected,
  • your AI says something that does not match what you remember.

An earlier message in your AI's chat describes a moment that has passed. The audit log shows selected decisions as they were recorded, in order. To check that an approved record landed, or to see its current state, open it in the Workspace.

Finding an entry

Above the list you can narrow it down:

  • Search decisions. Type a clause, the name of a record, or an action.
  • Kind. Show one kind of record, such as policies or risks.
  • Actor. Show what one person did.
  • From and To. Limit the list to a date range.

The page loads the most recent decisions first. Search and the filters cover the entries loaded so far, and the page tells you so. To look further back, choose Load older entries at the bottom and search again.

What one person did

On the team page in Settings, View activity next to a person opens the audit log filtered to them. Show all activity brings back the full list.

Checking the chain yourself

Choose Verify chain at the top of the log. Your browser checks that each loaded entry points at the one before it, and reports the result: either the chain is intact, with the number of entries that link correctly, or a break at a numbered entry. Until you run it, the label reads "Chain not verified this session".

The check runs in your browser, so you are not taking the dashboard's word for it. It covers the entries loaded on the page. The full proof, which also recomputes each entry's content and checks the signed chain root, is the offline verifier that comes with the export. Your auditor runs it without Kanonik.

If the check ever reports a break, do not rely on the record until it is explained. Download the export, run the offline verifier, and email [email protected].

Exporting it

Export audit pack at the bottom of the log produces the signed bundle for your auditor, with the offline verifier inside. If the pack carries a charge, the price is shown and you confirm it before anything is produced. Exporting your evidence for an audit covers what the pack holds and how your auditor checks it.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email [email protected] and a person who works on the product answers.