What eConnect Audits
eConnect records what people do. This page explains the shape of that record, what it can prove, and where to go to read it.
The short answer
Substantive actions are audited. Signing in and out, running and saving queries, viewing and closing cameras, acknowledging and ignoring alerts, editing subjects and plates, working cases, exporting video, generating reports, administrative changes, and using the Ace.
Every audited action, with the exact text it records, is listed in the Audit Catalog. That page is generated from the source, so it cannot drift from what the application actually does — it is the reference to consult when you need to know whether something is captured, before going looking for it.
What a row contains
| Field | Where it comes from |
|---|---|
| Who | The session, established server-side |
| Their user group | The session |
| Client address | The connection |
| When | Stamped by the server |
| What | An action type, and a description |
| Reference | The record concerned, where applicable |
Identity and time are established by the server, not sent by the application. A client cannot claim to be somebody else or backdate an action. That is what makes the record usable as evidence rather than merely as a log.
Descriptions are structured
Audit rows are not free text. Each action writes a consistent, predictable form:
CAMERA 'North Entrance' PLAYBACK @ '2026-09-01 14:03'
DASHBOARD 'Night Shift' OPENED
ALERTS MUTED FOR 30 MINUTES
SEARCHED FOR FACE WITH IDENTIFICATION 'Smith'
Because the wording is consistent, the trail can be searched for a pattern rather than read sequentially — which is what makes a year of history usable.
Two trails
| Audit trail | Activity log | |
|---|---|---|
| Purpose | The permanent record | A working record of one activity |
| Scope | Everything audited | Substantive actions while recording |
| Read from | Session History, audit trail | The activity log |
While an operator is recording an activity, substantive audited actions are mirrored onto it so the log reflects what was actually done. Navigation and assistant housekeeping are deliberately excluded — they would bury the real work.
What is not audited
- Reading a page is generally not recorded, though opening a module view is.
- What you typed into a search box, beyond what the description records.
- Passwords, ever — a change is recorded, the value is not.
- Your own Workspace tree, which is private working state.
Where to read it
| Question | Go to |
|---|---|
| What has this person been doing? | Session History |
| Who did this, in this period? | Reading the Audit Trail |
| Who can do what, right now? | The Security and Access Report |
| Is X audited, and what does it say? | Audit Catalog |
| How is eConnect being used overall? | Usage Statistics |
Telling users
Worth saying plainly to staff: their actions are recorded against their account, including questions asked of Ace. That is not a reason for anxiety — it is the reason a person can be cleared as readily as implicated, and it is why sharing credentials or leaving a workstation signed in is a genuinely bad idea.