Skip to main content

Audit App

App showcase

Investigate what NIM changed, when it happened, and which user or process initiated it.

The Audit App gives IT a searchable view of recorded NIM activity. It brings object, attribute, membership, app, and configuration-resource history together so administrators can investigate a change without starting with raw audit queries.

Intended audience

IT team

Target scope

All objects processed by NIM

Required systems

Any

When to use itDirect link to When to use it

Use this pattern when someone asks why an account changed, when a group membership was added or removed, or what ran before an unexpected result. Start with the affected object, attribute, actor, app, or resource, then narrow the history to the relevant event.

For example, if a user gained an unexpected group membership, IT can review membership activity for that object and identify the recorded time, operation, process, and actor before troubleshooting the underlying workflow.

How it helpsDirect link to How it helps

  • Find recorded activity for an object or attribute across connected systems.
  • Investigate who or what initiated a change and when it occurred.
  • Review app sessions and actions alongside changes to NIM configuration resources.
  • Filter recent logs by view and period to focus on a particular event or time frame.

Investigation flowDirect link to Investigation flow

Locate

Choose an audit viewStart with an object, attribute, actor, app, resource, or recent log

Narrow

Search or select a periodFind the relevant identity, operation, or time window

Trace

Follow the recorded activityReview the affected item, change type, process, actor, and time

Resolve

Investigate the source workflowUse the evidence to troubleshoot or explain the change
The app presents recorded audit data; the available history depends on what NIM has logged and retained.

OutcomeDirect link to Outcome

IT can answer change-history questions with a clearer trail of evidence and identify the workflow or actor to investigate next. For the underlying data model and query examples, see Auditing queries.

App previewDirect link to App preview

The example implementation is labeled Audit Logs in the screenshots. Its six views offer different starting points for the same investigation.

Start with an object and inspect its attribute or membership activity.
Find recorded changes for a particular attribute across a system.
Review activity associated with a user, administrator, or system process.
Inspect app sessions, actions, and errors.
Trace activity involving NIM configuration resources such as filters, mappings, and jobs.
Choose a view and period to inspect recent account and group membership events.