Request a demo →
AUDIT LOGS & INCIDENT EVIDENCE

When an incident occurs, clarity must follow.

Connect identity activity to people, systems, context and time.

Rainbow Secure records user and administrator activity across supported identity workflows to help teams investigate events, review sensitive access, answer audit questions and export evidence for further analysis.

INCIDENT EVIDENCE Reconstruct the access journey
01 Who?

Verified user or administrator

02 From where?

IP, device, location or platform

03 What happened?

Login, reset, access or policy event

04 Was access elevated?

Role, privilege or shared-account context

Structured evidence Timestamped · attributed · filterable · exportable
WHY EVIDENCE MATTERS

Security decisions need a record that can be reviewed later.

An alert may show that something happened. An activity record helps investigators establish who initiated it, what system was involved, which context was captured and what result followed.

01

Investigate incidents

Reconstruct authentication and access activity around a suspected compromise.

02

Review privileged use

Inspect how administrators and power users exercised sensitive access.

03

Attribute team access

Connect shared-account activity to the named person who initiated the journey.

04

Support audits

Filter and export relevant records for internal or external review.

WHAT RAINBOW SECURE CAPTURES

User activity and administrative change belong in the same evidence story.

Available fields depend on the workflow, enabled capabilities and connected system. The goal is consistent attribution across authentication, identity administration and governed access.

User activity logs

  • Successful and failed login attempts
  • MFA challenges and enforcement events
  • Device, platform, IP and location attributes
  • Session initiation and termination where captured
  • Risk-triggered authentication responses

Administrative activity logs

  • Role assignments and modifications
  • Privilege elevation events
  • Policy configuration updates
  • User provisioning and deprovisioning
  • IP block-management actions
  • Vault and privileged-access activity where enabled
REAL PRODUCT EXPERIENCE

Filter activity across groups, departments and applications.

The activity-history view lets reviewers narrow records by organization scope, platform and time period, then export the current view for further investigation or reporting.

  • Group and department filters
  • Application and platform filters
  • Configurable activity-history duration
  • User, device and IP context
  • Export of the current filtered view
Rainbow Secure activity-history report with filters and export controls
Rainbow Secure activity-history reporting
SPECIALIZED ACCOUNTABILITY REPORTS

See sensitive activity through the right operational lens.

Privileged and team accounts require more than a generic login count. Their reports focus on the people, accounts, source, time and actions needed for accountability.

Rainbow Secure privileged account usage report
PRIVILEGED ACCOUNT USAGE

Review administrator activity

Inspect power-user activity with identity, source IP, timestamp and recorded action, then filter or export the view.

Rainbow Secure team account usage report
TEAM ACCOUNT USAGE

Attribute shared-account access

Connect the team or shared account to the named person who completed the login journey.

EVIDENCE MODEL

Give every relevant event the context needed for review.

Rainbow Secure records are organized around a practical investigation model rather than an isolated authentication result.

01

Time

When the event occurred

02

Identity

Which verified user initiated it

03

Source

IP, device or platform context captured

04

Resource

Which application or account was involved

05

Action

What authentication or access event occurred

06

Outcome

Whether the event succeeded, failed or remained pending

FROM EVENT TO EVIDENCE

A repeatable path for investigation and audit support.

  1. 01 Define the question

    Identify the account, user, system or time window under review.

  2. 02 Filter the records

    Narrow activity by group, department, application, platform or duration.

  3. 03 Correlate context

    Review identity, IP, device, timestamp, action and outcome fields available.

  4. 04 Export the view

    Provide the relevant filtered dataset to the authorized investigation or audit process.

  5. 05 Preserve and govern

    Apply the organization’s retention, access-control and evidence-handling requirements.

EVIDENCE INTEGRITY

Searchability is operational. Integrity is architectural.

Rainbow Secure provides timestamped, attributed, filterable and exportable records. Evidence preservation also depends on the customer’s hosting model, retention settings, administrative access, export destination and chain-of-custody process.

For regulated or legal use, confirm retention, immutability, time synchronization, administrator separation and external archival requirements during technical discovery.

ACTIVITY LOGS FAQ

Questions buyers should resolve before relying on evidence.

Can reports be filtered and exported?+

Yes. Available reports support relevant filters and export controls. Exact fields and export options depend on the report, enabled capability and selected package.

Can shared-account activity be tied to an individual?+

Controlled Team Access is designed to connect the shared destination account with the named Rainbow Secure user who initiated the login journey.

Are logs tamper-proof?+

Rainbow Secure provides attributed activity records, but end-to-end tamper resistance depends on deployment architecture, administrative controls, retention configuration and any external immutable archive. Those requirements should be validated for the customer’s environment.

Can logs support compliance reviews?+

They can support access-control testing, investigation and audit preparation. Rainbow Secure does not automatically provide certification or determine whether evidence is legally sufficient.

Can activity be exported to a SIEM or data warehouse?+

Export and downstream integration requirements should be confirmed during technical discovery, including format, frequency, transport, retention and the selected package.

TURN ACTIVITY INTO ACCOUNTABILITY

Know what happened—and show the evidence behind the answer.

Bring one investigation, privileged-access review or compliance requirement to a guided session. We will map the required events, fields, filters, exports, retention and reviewers.

Logging coverage, fields, retention, export and integrations depend on enabled capabilities, supported systems, hosting model, selected package and approved configuration. Rainbow Secure supports investigations and audit preparation; it does not automatically make evidence immutable, legally admissible or sufficient for certification.