A compliance auditor reconstructing a trail with a stack of highlighters, marked-up printouts and a laptop at a long table.

CEDX Audit · Platform

An audit trail that
audits itself first.

Three hundred twenty events in the demo stream, and the console's first job is grading its own coverage: 6 of 24 sources passing validation, a digest chain at 72% integrity, and 15 retention gaps — because a trail with holes in it is worse than no trail at all.

The finding that writes the page: the identity production log retains 45 days against a 90-day compliance floor. Nobody tampered with anything — the trail just quietly stopped keeping what it should.

audit.cedxsystems.com — live build
CEDX Audit overview: events in stream, failures, high-risk findings, retention gaps, source health, integrity pass rate and root-caused alerts.

Runs on demo data. Northline Systems in the captures is the software's demo workspace, not a customer.

320 events in the 7-day stream124 of them admin-class — config or privilege
19 high-risk findingsanomaly and retention, scored 55 and above
6 of 24 sources healthyvalidation on; the digest chain passes 72%

What it is

A trail is only as good as its coverage.

Every event, typed and resulted

The event stream carries time, actor, action, target and result on all 320 rows: role assumes, policy updates, secret creates, lifecycle changes — with Success, Failure and Deny as filter chips. The 25 policy-blocked denies are counted separately, because a deny is the system working, not an error.

  • 320 rows searchable by actor, action, target, source
  • 65 failures = failure + deny, split on the header
  • Actions from device.enroll to trail.retention.update
audit — screen-3
Every event, typed and resulted

Risk scored, board by board

The Risk screen splits 72 rows into anomaly trails and retention risk, each with kind, actor, source, severity and score. Under-retained sources top the board at 89; impossible travel and off-hours bursts score in the 60s. The scoring model is a tab, not a secret.

  • 19 findings score 55 or above — 10 anomaly, 9 retention
  • Average anomaly 33 across 48 trails
  • Risk levers simulated: 5 rows, 2 levers
audit — screen-2
Risk scored, board by board

Actors profiled, break-glass counted

Ninety-six actors — human, service, break-glass, automation — with events, fails, risk and last seen per row. An automation at 8 events and 8 fails scores 93; the break-glass accounts are their own filter chip, because emergency access deserves its own list.

  • 96 actors: 40 elevated, 30 high risk
  • Average fail rate 33% across actors
  • Human · Service · Break-glass · Automation chips
audit — screen-4
Actors profiled, break-glass counted

Product tour

Four screens, captured from the running build.

Not a mockup and not a concept deck. This is what opens at /app/audit.

audit.cedxsystems.com
CEDX Audit Overview screen.CEDX Audit Risk screen.CEDX Audit Events screen.CEDX Audit Actors screen.

01 — Overview

Assurance health at 47 — and why

The assurance score is deliberately uncomfortable: integrity at 72%, only 6 of 24 sources healthy, 19 high-risk findings. The alerts are root-caused — an off-hours burst of 9 admin-class events in 74 minutes, a break-glass account assigned without a ticket, a digest window missing for two hours.

  • Severity mix: 135 info, 86 notice, 55 warning, 44 error
  • Sources by kind: SaaS 6, endpoint 5, cloud API 4 and more
  • High-score anomalies listed with actor and score

02 — Risk

The board, anomaly against retention

Seventy-two findings where the two failure modes sit side by side: things that happened and should not have, and records that should exist and do not. Filters at 55 and 70 turn the board into a work queue.

  • Anomaly trails: 48, retention risks: 24
  • Severity and score on every finding
  • CSV of the filtered board

03 — Events

The stream, row by row

Time to the second, actor, action, target, result. A secret create that failed sits two rows from a role assume that succeeded — the stream does not separate the good days from the bad ones, it just keeps both.

  • 124 admin-class events in the demo week
  • 25 denies, policy blocked
  • Search across actor, action, target, source

04 — Actors

Who did what, humans and otherwise

The actor table makes non-human activity visible: automations with perfect failure records, service accounts with elevated paths, break-glass principals with their own chip. Risk is scored per actor, and last-seen dates the row.

  • Automation actors scored like human ones
  • Break-glass filterable in one click
  • Department and event counts per actor

Who runs it

Three roles read the trail for a living.

Roles, not references. We have no named customers yet, so nobody in these photographs is quoted, credited or claimed as one.

Compliance

Owns the retention board: 15 gaps against the floor, the identity log 45 days short of 90, and the assurance score they report upward.

retention gaps · 15

Security review

Owns the anomaly board — 19 high-risk findings, the off-hours burst, the break-glass assignment without a ticket — and the review that follows.

high risk · 19

Platform engineering

Owns source coverage: 24 sources, 6 passing validation, and the digest windows that went missing for two hours.

sources healthy · 6/24

The shape of it

What the demo workspace actually looks like.

Every figure below is legible in the captures above. Nothing here is a projection of your estate — it is the state of the demo data.

320events in the stream7 days · 124 admin-class
65failuresfailure + deny · 25 policy-blocked
19high-risk findings10 anomaly · 9 retention
72%integrity passdigest chain, on screen
The risk board, top findingskind · actor · source · score
  • Under-retained network source — retention kind89
  • Service principal spike — anomaly kind80
  • Under-retained support SaaS — retention kind76
  • Under-retained endpoint fleet — retention kind70
  • Impossible travel pattern — anomaly kind66
Source validation6 of 24 sources passing
  • Healthy · 6 sources
  • Unvalidated or failing · 18 sources
Events by severity320 events in the 7-day stream
135
  • Info · 135
  • Notice 86 · warning 55 · error 44

How it runs

An event's life, in the order it actually happens.

01

Ingest

Twenty-four sources write into one stream — cloud API, identity, code platform, SaaS, endpoint, network — each validated on arrival.

02

Seal

Events chain into a digest; integrity passes 72% today, and the two-hour gap in one fleet's digest window is an alert, not a shrug.

03

Score

Anomaly and retention models run over the stream: 48 trails, 24 sources, 72 findings ranked by score.

04

Retain

Retention is checked against floors, not set-and-forgotten — the log 45 days under its 90-day floor is the finding that proves the check runs.

One record

The memory the whole
estate answers to.

Every admin-class action in the other products is an event here — the trail is how the estate explains itself later.

All 132 applications

Limits

What Audit does not do yet.

Finding this out on the third call is worse for you than reading it here, and worse for us.

Start

Open it before you talk to anyone.

Try

Open it right now

  • The live build
  • Demo data
  • No card, no call
Open live Audit

Pilot

Your sources, your floors

  • Everything in Try
  • Source-coverage plan
  • Retention-policy workshop
  • Estate map
Talk to sales

Estate

Audit with the rest of it

  • Audit with Identity, Admin and Directory
  • One trail, one bill
  • CEDX delivery
Book an estate map

Questions

Before you pilot Audit.

Is the software on this page real?

Yes. Every screenshot is a capture of the running build and you can open the same build at /app/audit. It runs on demo data, which the page says next to the figures rather than in a footnote.

What does the assurance score measure?

The trail's own trustworthiness: integrity pass rate (72% on the digest chain), source validation (6 of 24 healthy), admin-class volume and high-risk findings. It reads 47 in the demo — the product grading its own coverage before anyone else grades it.

What is a retention gap?

A source keeping less than its configured floor — 15 in the demo, topped by an identity production log at 45 days against a 90-day floor. Nothing was deleted maliciously; the configuration just drifted, which is what most audit findings actually look like.

How are anomalies found?

Forty-eight anomaly trails run over the stream: off-hours admin bursts, impossible travel, bulk exports, log-delete attempts. Each finding carries actor, source, severity and a score — the risk board tops out at 89 in the demo week.

What counts as an admin-class event?

Config and privilege changes — 124 of the 320 demo events: policy updates, role assumes, group membership changes, secret operations. They are counted separately because they are the events an assessor asks about first.

Is Audit itself audited or certified?

No certification has been issued for any CEDX product, Audit included — which this page states in its limits. What we can evidence about hosting, encryption, tenant isolation and production access is written up on the security page.

The console is running. Go and look at it.

Live build, demo data, no card. Then ask how many days of your own admin log you could actually produce.