Skip to main content

What eConnect Audits

eConnect records what people do. This page explains the shape of that record, what it can prove, and where to go to read it.

The short answer​

Substantive actions are audited. Signing in and out, running and saving queries, viewing and closing cameras, acknowledging and ignoring alerts, editing subjects and plates, working cases, exporting video, generating reports, administrative changes, and using the Ace.

Every audited action, with the exact text it records, is listed in the Audit Catalog. That page is generated from the source, so it cannot drift from what the application actually does — it is the reference to consult when you need to know whether something is captured, before going looking for it.

What a row contains​

FieldWhere it comes from
WhoThe session, established server-side
Their user groupThe session
Client addressThe connection
WhenStamped by the server
WhatAn action type, and a description
ReferenceThe record concerned, where applicable

Identity and time are established by the server, not sent by the application. A client cannot claim to be somebody else or backdate an action. That is what makes the record usable as evidence rather than merely as a log.

Descriptions are structured​

Audit rows are not free text. Each action writes a consistent, predictable form:

CAMERA 'North Entrance' PLAYBACK @ '2026-09-01 14:03'
DASHBOARD 'Night Shift' OPENED
ALERTS MUTED FOR 30 MINUTES
SEARCHED FOR FACE WITH IDENTIFICATION 'Smith'

Because the wording is consistent, the trail can be searched for a pattern rather than read sequentially — which is what makes a year of history usable.

Two trails​

Audit trailActivity log
PurposeThe permanent recordA working record of one activity
ScopeEverything auditedSubstantive actions while recording
Read fromSession History, audit trailThe activity log

While an operator is recording an activity, substantive audited actions are mirrored onto it so the log reflects what was actually done. Navigation and assistant housekeeping are deliberately excluded — they would bury the real work.

What is not audited​

  • Reading a page is generally not recorded, though opening a module view is.
  • What you typed into a search box, beyond what the description records.
  • Passwords, ever — a change is recorded, the value is not.
  • Your own Workspace tree, which is private working state.

Where to read it​

QuestionGo to
What has this person been doing?Session History
Who did this, in this period?Reading the Audit Trail
Who can do what, right now?The Security and Access Report
Is X audited, and what does it say?Audit Catalog
How is eConnect being used overall?Usage Statistics

Telling users​

Worth saying plainly to staff: their actions are recorded against their account, including questions asked of Ace. That is not a reason for anxiety — it is the reason a person can be cleared as readily as implicated, and it is why sharing credentials or leaving a workstation signed in is a genuinely bad idea.