Audit & Escalations
Role Required: REGIONAL_ADMIN
Navigation: Sidebar → Audit Logs
Last Updated: March 2026 | Portal Version: 1.0
Overview
As Regional Admin, you have cross-society audit access (AuditCrossSociety policy). You can view audit logs across all societies system-wide, track your own activity, and export data for investigations.
Audit Access
Your audit access allows:
| Feature | Available |
|---|---|
| Query audit logs across all societies (system-wide) | ✅ |
| Filter by entity type, action, user, severity, date | ✅ |
| Filter by specific society | ✅ |
| View your own activity history | ✅ |
| Export audit logs as CSV | ✅ |
| View summary statistics | ✅ |
| View individual entity audit history | ✅ |
| Modify audit settings | ❌ |
| View retention configuration | ❌ |
Querying Audit Logs
- Navigate to Audit Logs
- Use filters:
| Filter | Description |
|---|---|
| Search | Full-text search |
| Entity Type | Layout, Plot, Booking, Payment, etc. |
| Action | CREATE, UPDATE, DELETE, STATUS_CHANGE |
| Society | Filter to a specific society |
| User | Filter to a specific user |
| Severity | INFO / WARNING / CRITICAL |
| Date Range | Start and end date |
- Results show paginated audit entries with full details
My Activity
View all actions you've performed:
- Navigate to Audit Logs → My Activity
- See your complete audit trail
Exporting Data
- Apply your desired filters
- Click Export CSV
- Up to 10,000 entries exported
- CSV includes: Timestamp, EntityType, EntityId, Action, Severity, User, SocietyId, IP, Source, Summary
Escalation Procedures
When you identify an issue through monitoring or audit review:
Level 1: Society Admin Contact
For operational issues:
- Contact the Society Admin directly
- Share the specific concern (e.g., high refund rate, declining collections)
- Request an explanation or action plan
- Follow up within 48 hours
Level 2: Super Admin Escalation
For issues requiring higher authority:
- Contact the Super Admin
- Provide:
- Society name and ID
- Issue description
- Evidence from dashboard/reports/audit logs
- Actions already taken at Level 1
- The Super Admin can take direct action (block users, suspend societies, etc.)
When to Escalate
| Situation | Escalation Level |
|---|---|
| Society performance declining | Level 1 |
| Society Admin unresponsive | Level 2 |
| Financial irregularities detected | Level 2 |
| Suspicious audit trail activity | Level 2 |
| Alert not acknowledged for 72+ hours | Level 2 |
| Potential security breach | Level 2 (immediate) |
Investigating an Incident
Step-by-step investigation workflow:
- Define the scope: What happened, when, which society?
- Check audit logs: Filter to the relevant entity, time, and society
- Review the changes: Look at Old Values vs New Values
- Identify the actor: Who made the change (UserName, UserRole)
- Check for patterns: Use Correlation ID for bulk operations
- Gather evidence: Export filtered audit logs
- Report: Contact the appropriate escalation level with findings
Common Scenarios
"A society's financial data doesn't match expected values"
- Check audit logs for Entity Type =
Paymentand the society - Look for any UPDATE or DELETE actions on payment records
- Check if offline payments were voided after verification
- Export the relevant logs and escalate if needed
"A Society Admin reports they didn't make a change that appears in the system"
- Filter audit logs by the society and the entity in question
- Check the User ID, IP Address, and User Agent for each action
- If the action was made from an unexpected IP, this may indicate a security issue
- Escalate to Super Admin immediately
Related Pages
- Regional Dashboard — Alerts and activities
- Society Oversight — Society monitoring
- Audit & Activity Logs (Super Admin) — System-wide audit reference