Product updates have been moved to a new page. See the newest updates here

Auditing security considerations

This article is from before the rebranding to SelfGuide. Text and images can include the old product name ProductivityPerformer or its abbreviation PP.

Introduction

Insights into tenant usage can be valuable for identifying usage patterns, monitoring trends, or investigating unwanted scenarios.

Audit logging provides comprehensive visibility into product activity. It captures operations performed by all identities, including users viewing instructions, editors creating and maintaining content, and administrators modifying configurations.

While these insights are highly valuable, they also require careful handling due to the sensitive nature of the data involved.

Included data

The audit log file contains the following data:

  • Names of users
  • Operations performed by users
  • Timestamps indicating when an operation was performed

Recommendations for safe use

To ensure responsible handling of audit data, we recommend the following:

  • Only generate audit logs when necessary
  • Download and use audit data for a clearly defined purpose
  • Remove local copies after use
  • Avoid sharing or duplicating audit data outside the product environmen

Implemented measures

To help safeguard audit data, the following controls are in place:

  • Audit log files can only be generated and downloaded by accounts with an admin role
  • Generated audit log files are automatically deleted after 7 days
  • The generation and download of audit log files are also audited

ISO 27001:2022, certified by Brand Compliance