Overview
Good audit histories make investigations faster by surfacing meaningful context without hunting through unrelated records.
They should be searchable, understandable, and immutable once written.
Investigate immutable operational events
Search evidence, filter event types, pause or resume the stream, inspect an event, and prepare a governed export.
Activity and audit history
Aug 21, 2026
Anatomy
Use each piece in this order to keep interpretation and automation consistent.
- 1Actor timeline
Shows who initiated each event.
- 2Action descriptor
Clear action label and object impacted.
- 3Timestamp
Sortable and searchable event time information.
- 4Filters
Narrow by actor, action type, time window, and severity.
- 5Export hooks
Optional attachment for compliance evidence.
The ordering here is not visual-only; it reflects interaction priority and expected user cognition. Keep this order unless policy demands a specific domain exception.
When to use
Use this pattern when the user needs guided consistency, state, and reuse at scale.
Recommended
- High-trust operations
Use when every action may require review.
- Customer support
Use for post-incident traceability.
- Configuration management
Use for permission or policy edits.
When not to use
Avoid forcing this pattern where simpler, direct interactions are sufficient.
Avoid
- Real-time analytics
Use dedicated event streams where full event semantics differ.
- Simple changelog
Do not overload with audit requirements when lightweight history suffices.
- No retention policy
Avoid audit UI where retention policy is absent.
Variants
A small number of variants helps teams choose correctly without adding complexity.
Linear log
Single stream with search and sort controls.
Windowed audit
Date-window constrained view with preconfigured buckets.
Exporter
Governed export for review packets and case files.
States
States communicate readiness, risk, and expected user behavior.
| State | Trigger | Visual response | Interaction |
|---|---|---|---|
| Streaming | New events arriving | Top-updates appear by most recent | User can pause if desired. |
| Filtering | Log query applied | Filtered results count and noise reduction | Filters preserve current position for context. |
| Exported | Evidence requested | Generated artifact and status | User can copy or download artifact. |
Behavior
Behavior should remain predictable across devices, permissions, and async edges.
Contextual filters
Filter by actor, event type, and severity in one panel.
Searchable payload
Full-text hints for common investigation queries.
Tamper evidence
Immutable display from source event IDs.
Accessibility
Keep interaction clarity high and ensure assistive technologies get the same meaning.
| Key | Action |
|---|---|
| / | Focus the audit search field. |
| Tab | Advance through filters and list content in sequence. |
| Ctrl/CmdF | Open quick search within visible entries. |
- Describe event status with text and symbols.
- Keep timestamps in a consistent and localized format.
- Announce newly arrived rows when auto-refresh is enabled.
Content guidelines
Consistency is achieved by language standards, not by design only.
Event language
Use active voice and clear object references.
Alice approved invoice INV-102.
Priority labels
Use terms your support team already uses.
Critical change
Export naming
Use timestamps in export file naming.
audit-events-2026-08-18.csv
Examples
Reference implementation style, payloads, and practical behavior.
Production use
- Show actor, action, object, and result in a single sentence-like row.
- Add retention range controls aligned with compliance policy.
- Allow secure export for incident handover.
Props / API
Use these API entries as a baseline contract and validate them against your domain layer.
These names are implementation-oriented and should map to your local contracts.
Props