Audit Logs
Every significant action in QuantAssure is logged. When an auditor asks who did what and when — including what the AI decided — this is where you answer.
What's Logged
- All create, update, and delete operations
- Status changes on findings, action items, and controls
- User authentication events (login, logout, failed attempts)
- Risk acceptances and dismissals
- Report generation
- System configuration changes
- Team management actions (invites, removals)
- Integration sync events
- AI triage events
AI Decision Auditability
Every AI severity reclassification is logged as a
finding.severity_reclassified event — so when AI adjusts a
finding from its raw scanner severity, the audit trail records what changed
and when. Filter by that action to review every adjustment the AI has made.
For a point-in-time evidence export of every AI decision — original vs adjusted severity, reasoning, and confidence — generate the AI Decision Audit Trail report.
Viewing Audit Logs
- Navigate to Audit Log
-
Filter by:
- Entity type (finding, policy, system, user, etc.)
- Action (create, update, delete, status_change, etc.)
- User (who performed the action)
- Date range
- Search by entity name or description
- Each entry shows: timestamp, user, action, entity, and description
Exporting for Compliance
- Click "Export CSV" to download the filtered audit trail
- CSV exports are useful for IRAP evidence and internal audits
- Include date range filters to scope exports to audit periods
Tip: Export your audit trail as part of your IRAP evidence pack. Assessors value a clear record of security-related activities.