Three hundred twenty events in the demo stream, and the console's first job is grading its own coverage: 6 of 24 sources passing validation, a digest chain at 72% integrity, and 15 retention gaps — because a trail with holes in it is worse than no trail at all.
The finding that writes the page: the identity production log retains 45 days against a 90-day compliance floor. Nobody tampered with anything — the trail just quietly stopped keeping what it should.
audit.cedxsystems.com — live build
Runs on demo data. Northline Systems in the captures is the software's demo workspace, not a customer.
320 events in the 7-day stream124 of them admin-class — config or privilege
19 high-risk findingsanomaly and retention, scored 55 and above
6 of 24 sources healthyvalidation on; the digest chain passes 72%
What it is
A trail is only as good as its coverage.
Every event, typed and resulted
The event stream carries time, actor, action, target and result on all 320 rows: role assumes, policy updates, secret creates, lifecycle changes — with Success, Failure and Deny as filter chips. The 25 policy-blocked denies are counted separately, because a deny is the system working, not an error.
320 rows searchable by actor, action, target, source
65 failures = failure + deny, split on the header
Actions from device.enroll to trail.retention.update
audit — screen-3
Risk scored, board by board
The Risk screen splits 72 rows into anomaly trails and retention risk, each with kind, actor, source, severity and score. Under-retained sources top the board at 89; impossible travel and off-hours bursts score in the 60s. The scoring model is a tab, not a secret.
Ninety-six actors — human, service, break-glass, automation — with events, fails, risk and last seen per row. An automation at 8 events and 8 fails scores 93; the break-glass accounts are their own filter chip, because emergency access deserves its own list.
96 actors: 40 elevated, 30 high risk
Average fail rate 33% across actors
Human · Service · Break-glass · Automation chips
audit — screen-4
Product tour
Four screens, captured from the running build.
Not a mockup and not a concept deck. This is what opens at /app/audit.
audit.cedxsystems.com
01 — Overview
Assurance health at 47 — and why
The assurance score is deliberately uncomfortable: integrity at 72%, only 6 of 24 sources healthy, 19 high-risk findings. The alerts are root-caused — an off-hours burst of 9 admin-class events in 74 minutes, a break-glass account assigned without a ticket, a digest window missing for two hours.
Sources by kind: SaaS 6, endpoint 5, cloud API 4 and more
High-score anomalies listed with actor and score
02 — Risk
The board, anomaly against retention
Seventy-two findings where the two failure modes sit side by side: things that happened and should not have, and records that should exist and do not. Filters at 55 and 70 turn the board into a work queue.
Anomaly trails: 48, retention risks: 24
Severity and score on every finding
CSV of the filtered board
03 — Events
The stream, row by row
Time to the second, actor, action, target, result. A secret create that failed sits two rows from a role assume that succeeded — the stream does not separate the good days from the bad ones, it just keeps both.
124 admin-class events in the demo week
25 denies, policy blocked
Search across actor, action, target, source
04 — Actors
Who did what, humans and otherwise
The actor table makes non-human activity visible: automations with perfect failure records, service accounts with elevated paths, break-glass principals with their own chip. Risk is scored per actor, and last-seen dates the row.
Automation actors scored like human ones
Break-glass filterable in one click
Department and event counts per actor
Who runs it
Three roles read the trail for a living.
Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.
Compliance
Owns the retention board: 15 gaps against the floor, the identity log 45 days short of 90, and the assurance score they report upward.
retention gaps · 15
Security review
Owns the anomaly board — 19 high-risk findings, the off-hours burst, the break-glass assignment without a ticket — and the review that follows.
high risk · 19
Platform engineering
Owns source coverage: 24 sources, 6 passing validation, and the digest windows that went missing for two hours.
sources healthy · 6/24
The shape of it
What the demo workspace actually looks like.
Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.
320events in the stream7 days · 124 admin-class
65failuresfailure + deny · 25 policy-blocked
19high-risk findings10 anomaly · 9 retention
72%integrity passdigest chain, on screen
The risk board, top findingskind · actor · source · score
Under-retained network source — retention kind89
Service principal spike — anomaly kind80
Under-retained support SaaS — retention kind76
Under-retained endpoint fleet — retention kind70
Impossible travel pattern — anomaly kind66
Source validation6 of 24 sources passing
Healthy · 6 sources
Unvalidated or failing · 18 sources
Events by severity320 events in the 7-day stream
135
Info · 135
Notice 86 · warning 55 · error 44
How it runs
An event's life, in the order it actually happens.
01
Ingest
Twenty-four sources write into one stream — cloud API, identity, code platform, SaaS, endpoint, network — each validated on arrival.
02
Seal
Events chain into a digest; integrity passes 72% today, and the two-hour gap in one fleet's digest window is an alert, not a shrug.
03
Score
Anomaly and retention models run over the stream: 48 trails, 24 sources, 72 findings ranked by score.
04
Retain
Retention is checked against floors, not set-and-forgotten — the log 45 days under its 90-day floor is the finding that proves the check runs.
One record
The memory the whole estate answers to.
Every admin-class action in the other products is an event here — the trail is how the estate explains itself later.
Finding this out on the third call is worse for you than reading it here, and worse for us.
Audit is not generally available. What opens today is the live build running on demo data — Northline Systems in the captures is the software's demo workspace, not a customer.
We have no named customers to show you, so this page shows none. The actors named inside the demo captures are fictional rows in demo data.
The digest chain and integrity scoring are the demo build's mechanism, shown because it is inspectable. We are not claiming a third-party attestation of the chain — none exists.
Retention floors in the demo are configuration, not a claim about what your regulators require; the 90-day floor in the alert is the demo tenant's own policy.
The 24 demo sources are estate products. Third-party log-source coverage is not evidenced by these captures and is not claimed here.
No audit or compliance certification has been issued for Audit — an audit trail product without its own certification, stated plainly. What we can evidence about hosting, encryption and access is on the security page.
Yes. Every screenshot is a capture of the running build and you can open the same build at /app/audit. It runs on demo data, which the page says next to the figures rather than in a footnote.
What does the assurance score measure?
The trail's own trustworthiness: integrity pass rate (72% on the digest chain), source validation (6 of 24 healthy), admin-class volume and high-risk findings. It reads 47 in the demo — the product grading its own coverage before anyone else grades it.
What is a retention gap?
A source keeping less than its configured floor — 15 in the demo, topped by an identity production log at 45 days against a 90-day floor. Nothing was deleted maliciously; the configuration just drifted, which is what most audit findings actually look like.
How are anomalies found?
Forty-eight anomaly trails run over the stream: off-hours admin bursts, impossible travel, bulk exports, log-delete attempts. Each finding carries actor, source, severity and a score — the risk board tops out at 89 in the demo week.
What counts as an admin-class event?
Config and privilege changes — 124 of the 320 demo events: policy updates, role assumes, group membership changes, secret operations. They are counted separately because they are the events an assessor asks about first.
Is Audit itself audited or certified?
No certification has been issued for any CEDX product, Audit included — which this page states in its limits. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.
The console is running. Go and look at it.
Live build, demo data, no card. Then ask how many days of your own admin log you could actually produce.