Documentation Drift and Audit

Use the audit history

Use actor, action, target, environment, and time information to understand changes.

Audit history helps answer who performed an action, what changed, where it happened, when it occurred, and whether it succeeded. Use it to investigate unexpected behavior and support operational review.

Start with a narrow question

Choose a workflow, environment, deployment, secret reference, user, or time window. A narrow search is easier to interpret than a full history export.

Read an event

  • Actor: the user or service that initiated the action
  • Action: the requested operation
  • Target: the affected workflow or resource
  • Environment: the destination or context
  • Time: when the event was recorded
  • Result: success, failure, or another recorded state
  • Reference: an identifier used to correlate related records

Correlate, do not assume

An audit event records an operation; it may not prove the business outcome of the workflow. Compare it with the deployment record, environment status, workflow version, drift findings, and appropriate runtime evidence.

Share audit information safely

Use event and correlation identifiers when contacting support. Remove unrelated personal or customer data from exports. Audit history should not contain secret values; if you believe a value has been exposed, stop sharing the record and report it immediately.

Retention and exports

Availability, retention, and export options depend on the current service configuration and plan. Confirm your organization’s evidence requirements before relying on the service as the only record.