Version: 1.0
Last Updated: September 2026
1. Overview
Nova IAM records logins and changes to accounts, roles and requests in an audit log with actor, time, target and origin, including actions taken via the AI chat. There is no function in the UI or API to edit or delete entries. The audit log supports accountability and traceability in audits.
2. Audit Log Schema
| Field |
Type |
Description |
id |
Serial |
Unique, sequential event identifier |
timestamp |
Timestamp |
Server-generated event time (PostgreSQL NOW()) |
event_type |
Text |
Action identifier (e.g., login, role_assign) |
category |
Text |
Logical grouping (e.g., auth, roles, users) |
actor_id |
Integer |
ID of the user who performed the action |
actor_name |
Text |
Name of the acting user (resolved at log time) |
target_type |
Text |
Type of affected object (e.g., user, role) |
target_id |
Text |
Identifier of the affected object |
target_name |
Text |
Human-readable name of the affected object |
details |
JSONB |
Structured context of the change; via marks the origin, e.g. ai_chat:<assistant> |
ip_address |
Text |
Client IP address of the actor |
3. Audited Event Categories
Authentication Events
| Event Type |
Trigger |
Details Captured |
login |
Successful authentication |
Actor ID, IP address |
logout |
Session termination |
Actor ID, IP address |
set_password |
Password change |
Actor (who changed), target (whose password) |
User Management Events
| Event Type |
Trigger |
Details Captured |
create_user |
New user created |
User name, email, department |
update_user |
User profile modified |
Changed fields and values |
deactivate_user |
User status set to inactive |
Actor, reason |
Access Management Events
| Event Type |
Trigger |
Details Captured |
role_assign |
Entitlement assigned to user |
Role name, assignment type (direct/indirect) |
role_revoke |
Entitlement removed from user |
Role name, removal reason |
br_assign |
Business role assigned |
Business role name, validity dates |
br_revoke |
Business role removed |
Business role name |
nova_roles_update |
Nova IAM entitlements changed |
Added/removed role lists |
Provisioning Events
| Event Type |
Trigger |
Details Captured |
provision_sap |
SAP role sync executed |
System name, roles provisioned, success/failure |
provision_ldap |
LDAP group sync executed |
System name, groups added/removed |
provision_entra |
Entra group sync executed |
System name, groups added/removed |
System Events
| Event Type |
Trigger |
Details Captured |
settings_change |
Application settings modified |
Setting key, actor |
system_create |
Target system configured |
System name, type |
job_run |
Background job executed |
Job type, status, duration |
4. Integrity and Limits
Editing and Deletion
- There is no function in the UI or API to edit or delete audit log entries
- The audit log is a regular database table; write protection at database level (for example a trigger or revoked UPDATE/DELETE rights) is not part of the standard installation
Timestamp Integrity
- Timestamps are generated by the PostgreSQL server (
NOW()) at insert time
- Timestamps are not supplied by the application, preventing client-side manipulation
- Sequential
id column provides ordering guarantee
Actor Accountability
- Actor identity is captured from the authenticated server-side session
- Actor ID cannot be forged without a valid session
- IP address is captured from the request metadata
5. Retention & Access
Retention Policy
- Audit logs are retained indefinitely by default
- Audit log retention is managed at database level by the customer
- Forwarding to a SIEM: today via database export; a native forwarder is planned
Access Controls
- Audit log viewing is restricted to authenticated administrators
- Audit log API supports filtering by:
- Date range
- Event category
- Actor
- Target
- Bulk export available for compliance reporting
6. Regulatory Alignment
| Regulation |
Requirement |
Nova IAM Coverage |
| SOC 2 |
Logging of access and changes |
Audit log with actor, target, timestamp, IP and origin |
| GDPR Art. 30 |
Records of processing activities |
Supports the controller's records: changes to accounts, roles and requests are logged |
| ISO/IEC 27001:2022 A.8.15 |
Logging |
Logging of security-relevant events and changes |