Overview
Maintaining a clear, verifiable record of access removal during employee offboarding is essential for security compliance and audit readiness (such as SOC 2, ISO 27001, and NIST).
With Swifteam’s Employee Activity Log & Report Generation feature, administrators can track both automatic (SCIM) and manual application deprovisioning events, review historical lifecycle changes, and export comprehensive audit reports in CSV and PDF formats.
1. Viewing an Employee's Activity Log
You can view the full lifecycle and offboarding history directly within an employee’s profile:
In the Swifteam dashboard, navigate to Employees and select the desired employee.
Click on the Activity Log tab.
The activity history is presented as a structured table displaying major status changes (e.g., Onboarded, Deactivated).
For events with associated deprovisioning actions, click the chevron / expand icon next to the status row to view the detailed breakdown.
2. Understanding Deprovisioning Metadata
When expanding an offboarding or deprovisioning event, the nested table displays the following audit details for each assigned application:
Field | Description |
App | The application name and icon. |
Status | Shows |
Method | Indicates whether access was removed via |
Performed By | For Automatic, shows the admin who initiated the workflow. For Manual, records the specific admin who verified and clicked Mark as Completed. |
Completed At | The exact timestamp when access was successfully revoked or marked complete. |
Deprovisioning Method Badges & Tooltips
Automatic (SCIM): Hovering over the badge displays "This app supports automatic deprovisioning via SCIM." These tasks complete automatically and record instant confirmation.
Manual: Hovering over the badge displays "This app requires manual deprovisioning. An admin must remove access directly in the app."
3. Persistent Audit Trail & Reactivations
To support compliance standards, Swifteam preserves all audit trail records indefinitely:
Employee Reactivation: If a deactivated employee is later reactivated, their past offboarding records, timestamps, and performer metadata remain intact and accessible in their historical log.
Interrupted Workflows: If an offboarding workflow is paused or interrupted, completed application records remain safely saved and auditable.
4. Generating & Exporting Cross-Employee Reports
Administrators can generate unified audit reports across multiple team members to share with auditors or internal compliance teams.
Steps to Generate a Report:
Navigate to Employees > [Any Employee Profile] > Activity Log tab.
Click the Generate Report button located at the top of the table to open the dedicated report page.
Apply filters to narrow down the report:
Employee: Select specific employees or keep All employees (default).
Status: Filter by lifecycle status (e.g.,
Deactivated). This includes any employee who held the status at any point in their history.Date Ranges: Set custom boundaries for Onboarded Date or Deactivated Date.
Review the real-time preview table showing cross-employee status histories and application deprovisioning records.
Downloading the Report:
Click the Download Report dropdown in the top-right corner.
Select your preferred file format:
CSV (for spreadsheet analysis and data processing)
PDF (for audit-ready compliance evidence)
A confirmation notification will appear when the report has been generated and downloaded.
Frequently Asked Questions (FAQ)
Q: Does filtering by "Deactivated" only show currently deactivated employees?
A: No. Filtering by status includes historical matching. It returns any employee who held the Deactivated status at any point in their history, ensuring past offboardings are captured even if an account was reactivated.
Q: What happens if an automatic SCIM deprovisioning fails?
A: If an automated deprovisioning fails, the event log records the failure status so admins can review and take manual remediation actions.

