Audit Trail Documentation

Zielgruppe: Auditoren · Compliance Status: Aktiv

Version: 1.0 Last Updated: September 2026


1. Overview

Nova IAM records logins and changes to accounts, roles and requests in an audit log with actor, time, target and origin, including actions taken via the AI chat. There is no function in the UI or API to edit or delete entries. The audit log supports accountability and traceability in audits.

2. Audit Log Schema

Field Type Description
id Serial Unique, sequential event identifier
timestamp Timestamp Server-generated event time (PostgreSQL NOW())
event_type Text Action identifier (e.g., login, role_assign)
category Text Logical grouping (e.g., auth, roles, users)
actor_id Integer ID of the user who performed the action
actor_name Text Name of the acting user (resolved at log time)
target_type Text Type of affected object (e.g., user, role)
target_id Text Identifier of the affected object
target_name Text Human-readable name of the affected object
details JSONB Structured context of the change; via marks the origin, e.g. ai_chat:<assistant>
ip_address Text Client IP address of the actor

3. Audited Event Categories

Authentication Events

Event Type Trigger Details Captured
login Successful authentication Actor ID, IP address
logout Session termination Actor ID, IP address
set_password Password change Actor (who changed), target (whose password)

User Management Events

Event Type Trigger Details Captured
create_user New user created User name, email, department
update_user User profile modified Changed fields and values
deactivate_user User status set to inactive Actor, reason

Access Management Events

Event Type Trigger Details Captured
role_assign Entitlement assigned to user Role name, assignment type (direct/indirect)
role_revoke Entitlement removed from user Role name, removal reason
br_assign Business role assigned Business role name, validity dates
br_revoke Business role removed Business role name
nova_roles_update Nova IAM entitlements changed Added/removed role lists

Provisioning Events

Event Type Trigger Details Captured
provision_sap SAP role sync executed System name, roles provisioned, success/failure
provision_ldap LDAP group sync executed System name, groups added/removed
provision_entra Entra group sync executed System name, groups added/removed

System Events

Event Type Trigger Details Captured
settings_change Application settings modified Setting key, actor
system_create Target system configured System name, type
job_run Background job executed Job type, status, duration

4. Integrity and Limits

Editing and Deletion

  • There is no function in the UI or API to edit or delete audit log entries
  • The audit log is a regular database table; write protection at database level (for example a trigger or revoked UPDATE/DELETE rights) is not part of the standard installation

Timestamp Integrity

  • Timestamps are generated by the PostgreSQL server (NOW()) at insert time
  • Timestamps are not supplied by the application, preventing client-side manipulation
  • Sequential id column provides ordering guarantee

Actor Accountability

  • Actor identity is captured from the authenticated server-side session
  • Actor ID cannot be forged without a valid session
  • IP address is captured from the request metadata

5. Retention & Access

Retention Policy

  • Audit logs are retained indefinitely by default
  • Audit log retention is managed at database level by the customer
  • Forwarding to a SIEM: today via database export; a native forwarder is planned

Access Controls

  • Audit log viewing is restricted to authenticated administrators
  • Audit log API supports filtering by:
    • Date range
    • Event category
    • Actor
    • Target
  • Bulk export available for compliance reporting

6. Regulatory Alignment

Regulation Requirement Nova IAM Coverage
SOC 2 Logging of access and changes Audit log with actor, target, timestamp, IP and origin
GDPR Art. 30 Records of processing activities Supports the controller's records: changes to accounts, roles and requests are logged
ISO/IEC 27001:2022 A.8.15 Logging Logging of security-relevant events and changes
Fragen zu diesem Dokument? Schreiben Sie an trust@nova-iam.com – wir bestätigen den Eingang innerhalb von 2 Werktagen.