Skip to main content

Understanding Audit Trail

Swif is dedicated to ensuring transparency and accountability for all administrative actions. The Audit Trail feature lets organizations monitor and review actions performed by team administrators, improving operational oversight, security, and compliance.

You can access audit data in two ways:

  • A notification-style Audit Trail panel for quick reviews of recent activity (with Unread, All, and Trash tabs).

  • The full Audit Trail page for deeper filtering and investigation.


What Is Tracked in the Audit Trail?

The audit trail records key administrative actions across multiple areas of your Swif tenant. Each entry captures who performed the action, what changed (including field-level diffs with previous and new values where applicable), which objects were affected, and when it occurred.

1. Device Management

Actions related to managed devices, such as:

  • Adding or removing devices

  • Assigning or unassigning devices to employees

  • Archiving or restoring device records

  • Locking or unlocking devices

  • Reassigning devices to new employees

  • Uploading receipts or invoices for devices

These events help you understand who changed device ownership, security state, or inventory details.

2. Device Actions (MDM)

Remote actions triggered via MDM, including:

  • Restart — Restarting a device

  • Shutdown — Shutting down a device

  • Wipe/Erase — Erasing a device remotely

Each action logs the actor, device name, device ID, and timestamp.

3. Device Account Actions (MDM)

User account management actions on managed devices:

  • Create Account — Creating a user account on a device

  • Delete Account — Deleting a user account from a device

  • Lock Account — Locking a user account on a device

  • Unlock Account — Unlocking a user account on a device

Each entry records the actor, account name, device name, device ID, and timestamp.

4. Team Management

Actions related to how teams are structured and managed, including:

  • Creating or deleting teams

  • Updating team configurations

  • Inviting or revoking invitations for team members

These records provide visibility into who can access which teams and when those changes were made.

5. Employee Records

Changes to employee profiles and access, such as:

  • Adding or removing employee profiles

  • Updating employee details

  • Sending role-based invitations to employees

  • Inviting employees to enroll devices

This makes it easy to trace when employees were onboarded, offboarded, or had their access changed.

6. Organizational Settings

Tenant-level configuration changes, including:

  • Modifying organizational configurations

  • Enabling or disabling specific features (for example, remote desktop, app tracking, or Swif IQ)

  • Managing tasks within to-do lists

  • Updating the organizational address book

These logs are especially important for compliance and security reviews.

7. Policies

CRUD operations on policies:

  • Create — Creating a new policy (including from Compliance Center or Security compliance controls)

  • Update — Modifying an existing policy's name or settings

  • Delete — Removing a policy

Example: "Angelo Huang created policy Linux Firmware Update Policy"

8. Commands

CRUD operations on custom commands/scripts:

  • Create — Creating a new command

  • Update — Modifying a command's name or script content

  • Delete — Removing a command

9. Applications / Software

CRUD operations on managed applications:

  • Create — Adding a new application to the catalog

  • Update — Modifying an application's configuration

  • Delete — Removing an application

10. MSP Management

Actions related to Managed Service Provider operations:

  • Creating, updating, or deleting MSP configurations

11. API Clients

Changes to API client configurations:

  • Creating, updating, or deleting API clients

  • Extension attributes CRUD operations

12. Onboarding / Offboarding

Changes to onboarding and offboarding workflows:

  • Creating, updating, or deleting onboarding/offboarding configurations

13. Compliance

Changes to compliance-related configurations:

  • Creating, updating, or deleting compliance controls and settings

14. Merge Operations

Audit trail entries for merge operations:

  • Merge Employee Records — When duplicate employee records are merged, an entry captures the actor, source and target employee records, timestamp, and affected fields/data.

  • Merge Devices — When duplicate devices are merged, an entry captures the actor, source and target device records, timestamp, and affected device identifiers.

Field-Level Diffs

For create and update operations, the audit trail captures field-level diffs showing:

  • The previous value before the change

  • The new value after the change

  • Which specific fields were modified

This allows administrators to see exactly what was changed, not just that a change occurred.


How to Access the Audit Trail

You can review audit data from both the notification panel and the full Audit Trail page.

A. Opening the Audit Trail Notification Panel

  1. Log in to your Swif Admin Panel.

  2. Click the Audit Trail icon in the left navigation or app header (depending on your layout).

  3. The Audit Trail notification panel opens, showing recent activity.

In the panel, you'll see:

  • Tabs:

    • Unread (default) — actions you haven't marked as read

    • All — both read and unread actions

    • Trash — actions you've moved to trash

  • Per-admin unread counts

    • The unread count is user-specific.

    • Example: if there are 5 total trails and Admin A has read 2, their unread count is 3; Admin B has read 1, their unread count is 4.

  • Action buttons (on hover):

    • Unread tab: Mark as read, Trash

    • All tab: Mark as unread, Trash

    • Trash tab: Restore, Delete permanently

  • Empty states — When a tab has no records, you'll see a dedicated empty-state message.

  • Blue dot indicator — When you have unread audit trails, a blue dot appears on the Audit Trail icon, so admins can quickly see there's new activity.

  • "View all" button — Click View all to navigate to the full Audit Trail page for deeper analysis.

Note: The All tab includes both read and unread items by design. New notifications appear in Unread and also in All.

B. Using the Full Audit Trail Page

For more detailed investigation, use the dedicated Audit Trail page:

  1. From the Audit Trail panel, click View all, or go to the Audit Logs / Audit Trail item in the left navigation.

  2. On the full page, you can:

    • Search audit records (searches across all fields including policy names, command names, and other details)

    • Filter by date range using the calendar

    • View detailed information for each action (who did what, where, and when)

The full page is designed for:

  • Reviewing longer histories

  • Applying filters and date ranges

  • Exporting or reporting (where available)

  • Supporting internal audits and investigations

Why Audit Trails Are Important

Audit trails are a core part of secure and compliant operations.

1. Compliance — Demonstrate that administrative actions follow your organization's policies. Support audits by providing a clear record of changes to devices, teams, policies, and configuration.

2. Accountability — See which admin performed an action, and when. Quickly identify the source of unexpected changes or configuration issues.

3. Transparency — Give security, IT, and compliance teams a shared, factual view of how the environment is being managed.

4. Troubleshooting — Trace sequences of actions that led to an incident or user-reported problem. Validate whether a certain change actually occurred and by whom.

Role-Based Access and Permissions

Access to audit data is role-based:

  • Account Owners and appropriately permissioned admins can view audit trail.

  • Certain actions or views may be restricted for non-owner roles, depending on your organization's configuration.

This ensures that sensitive administrative history remains visible only to authorized users.

Summary

Swif's Audit Trail provides a comprehensive, detailed record of administrator activity across devices, MDM actions, teams, employees, policies, commands, applications, API clients, compliance, MSP configurations, onboarding/offboarding, merge operations, and organizational settings.

With:

  • A notification-style Audit Trail panel (Unread / All / Trash, with per-admin unread counts and action buttons), and

  • A full Audit Trail page with search and date range filters,

Your organization gains strong visibility, better compliance posture, and faster troubleshooting capabilities.

If you need help reviewing or interpreting audit data, contact us at support@swif.ai or via the in-app chat.

Did this answer your question?