The audit report
Corelog exports one report in two formats — a paginated PDF and a Markdown file for a ticket. Both are built from the same calculation, so they cannot disagree about the same export, and a figure that appears in either can be traced to the section that produced it.
The report is about the file, not about a person. It describes what an export contains, whether that is one account or ten thousand.
What is in it
Section titled “What is in it”| Section | What it carries |
|---|---|
| Cover | Source file, SHA-256, period, events, accounts, workloads, time zone, availability window, declared networks, whether identifiers were anonymised |
| Summary | Calculated prose — every sentence built from a figure that appears further down |
| What this source is | What a unified audit log export is, and what it is not |
| Method and limitations | Thresholds, the exclusion list with counts, prefix grouping, and the two hours figures explained |
| Time spent working | Week by week, on two tracks, with the unfiltered control beside them |
| Activity matrix | Events per account per bucket, printed as numbers |
| Activity by account | One row per account, capped and the cap declared |
| Where the activity came from | Every address with its operator, city, volume and whether it is declared |
| Behaviour shifts | Statistical change-point detection, or why it did not run |
| Detections | Counts per detection, and the exact criteria each one tested |
| Examined and clear | See below |
| Geography | Countries resolved from addresses |
| Conclusions and next steps | Calculated, and deliberately not a verdict |
| Appendix | The individual flagged events, pinned events and your notes |
Examined and clear
Section titled “Examined and clear”Most generated reports say what fired and never what was looked at and found nothing. That asymmetry is what makes them read like an accusation: a check that stays silent disappears, and a reader cannot tell “no external sharing happened” from “external sharing was never checked”.
So the report asks seven questions beyond the detections — external sharing, anonymous links, bulk downloads, group and role changes, failed sign-ins, blocked actions and mail forwarding — and each one reports what it examined, how many of those events carried the evidence its answer rests on, and a verdict with three values:
- Examined — clear. It was looked at and there is nothing to look at.
- To review. Something a reader has to see.
- Could not be answered. The export does not carry the field the question needs.
The third is the one that matters. On a reference export there are 466 sharing events and only 71 name a recipient that can be placed. The honest sentence names both figures and says the answer covers 15% of the sharing activity — “no external sharing” would have been an invention about the other 395. Where no event names a recipient at all, the verdict is could not be answered, never clear, and the report says which field is missing.
Recipients are placed inside or outside the organisation by comparing their domain against the tenant’s own, inferred from the accounts that performed the logged actions. Subdomains count as internal. The report prints the inference and the domains it used, so you can judge it rather than trust it.
Two hours figures, on purpose
Section titled “Two hours figures, on purpose”The method section carries a fixed paragraph explaining the difference between active hours (how much) and confirmed hours (where), because they answer different questions and the first will always be smaller. See Presence.
The time section also prints the control: the same arithmetic with nothing excluded. On the reference export that is 1,734 hours and a busiest week of 103.8 out of the 168 a week contains. It is printed because an estimate nobody can sanity-check is not an estimate.
Caps are stated, never silent
Section titled “Caps are stated, never silent”Long tables are capped — accounts, addresses, weeks, flagged events — and every cap prints what was left out and how the totals still cover everything. A report that quietly truncated would be worse than one that printed 200 pages.
Where an analysis could not run
Section titled “Where an analysis could not run”Every section that can fail says so instead of showing an empty result. Change-point detection that never ran, a time estimate with no declared network, a geography column whose database did not load: each states the reason. “Nothing found” and “could not look” are different answers, and this document never renders them the same way.
Anonymisation
Section titled “Anonymisation”With the anonymisation switch on, the report replaces, in field values and inside detection prose alike:
- accounts and every UPN variant
- addresses, in both the raw and normalised forms Purview writes
- devices and machine identifiers
- filenames
- sharing recipients and forwarding addresses
- the tenant’s own domains
- declared-network labels
Declared network prefixes are omitted entirely, because a prefix is not the address of any event and has no alias to take.
City, region, country and network operator are not anonymised. A report whose locations
read city_4f2a answers nothing, and they are the point of the geography section. The
cover states this, so a reader knows what the label covers.
No branding
Section titled “No branding”Nothing in the PDF names the product or the company — not the cover, not the page footers, not the file’s metadata. It is meant to be handed to a client, an auditor or a court as it is. The Markdown export still carries a title and a footer line, since it is normally pasted into a ticket rather than sent onward.