Audit Trail

Cloud Email Protection creates a thorough and detailed audit trail to document and authenticate all activity in an organization. All activity is listed in reverse chronological order on the Audit the activity log pages for both your organization (see View Organization Activity) and each user (see View User Activity) in your organization. The list uses icons to categorize the type of activity.

On the Audit log page, click the "Help" icon (question mark) at the top of the page for more information about searching and using the log.

Icon Activity Category
Indicates that the user signed in, either of Cloud Email Protection itself or an organization in Cloud Email Protection.
Indicates that the user signed out, either of Cloud Email Protection itself or an organization in Cloud Email Protection.
Indicates that the user created, edited, or deleted a user account, policy, or address group.
Indicates that the user created, edited, deleted, or performed other actions on a domain.
Indicates that the user created, edited, deleted, or performed other actions on a sender.
Indicates that the user created a report request.
Indicates that the user created, edited, deleted, or performed other actions on a domain group.
Indicates that a user performed an organization-level activity, such as accepting the Fortra End-User License Agreement (EULA) or changing organization settings.