Skip to content

The audit report

Corelog exports one report in two formats — a paginated PDF and a Markdown file for a ticket. Both are built from the same calculation, so they cannot disagree about the same export, and a figure that appears in either can be traced to the section that produced it.

The report is about the file, not about a person. It describes what an export contains, whether that is one account or ten thousand.

Section What it carries
Cover Source file, SHA-256, period, events, accounts, workloads, time zone, availability window, declared networks, whether identifiers were anonymised
Summary Calculated prose — every sentence built from a figure that appears further down
What this source is What a unified audit log export is, and what it is not
Method and limitations Thresholds, the exclusion list with counts, prefix grouping, and the two hours figures explained
Time spent working Week by week, on two tracks, with the unfiltered control beside them
Activity matrix Events per account per bucket, printed as numbers
Activity by account One row per account, capped and the cap declared
Where the activity came from Every address with its operator, city, volume and whether it is declared
Behaviour shifts Statistical change-point detection, or why it did not run
Detections Counts per detection, and the exact criteria each one tested
Examined and clear See below
Geography Countries resolved from addresses
Conclusions and next steps Calculated, and deliberately not a verdict
Appendix The individual flagged events, pinned events and your notes

Most generated reports say what fired and never what was looked at and found nothing. That asymmetry is what makes them read like an accusation: a check that stays silent disappears, and a reader cannot tell “no external sharing happened” from “external sharing was never checked”.

So the report asks seven questions beyond the detections — external sharing, anonymous links, bulk downloads, group and role changes, failed sign-ins, blocked actions and mail forwarding — and each one reports what it examined, how many of those events carried the evidence its answer rests on, and a verdict with three values:

  • Examined — clear. It was looked at and there is nothing to look at.
  • To review. Something a reader has to see.
  • Could not be answered. The export does not carry the field the question needs.

The third is the one that matters. On a reference export there are 466 sharing events and only 71 name a recipient that can be placed. The honest sentence names both figures and says the answer covers 15% of the sharing activity — “no external sharing” would have been an invention about the other 395. Where no event names a recipient at all, the verdict is could not be answered, never clear, and the report says which field is missing.

Recipients are placed inside or outside the organisation by comparing their domain against the tenant’s own, inferred from the accounts that performed the logged actions. Subdomains count as internal. The report prints the inference and the domains it used, so you can judge it rather than trust it.

The method section carries a fixed paragraph explaining the difference between active hours (how much) and confirmed hours (where), because they answer different questions and the first will always be smaller. See Presence.

The time section also prints the control: the same arithmetic with nothing excluded. On the reference export that is 1,734 hours and a busiest week of 103.8 out of the 168 a week contains. It is printed because an estimate nobody can sanity-check is not an estimate.

Long tables are capped — accounts, addresses, weeks, flagged events — and every cap prints what was left out and how the totals still cover everything. A report that quietly truncated would be worse than one that printed 200 pages.

Every section that can fail says so instead of showing an empty result. Change-point detection that never ran, a time estimate with no declared network, a geography column whose database did not load: each states the reason. “Nothing found” and “could not look” are different answers, and this document never renders them the same way.

With the anonymisation switch on, the report replaces, in field values and inside detection prose alike:

  • accounts and every UPN variant
  • addresses, in both the raw and normalised forms Purview writes
  • devices and machine identifiers
  • filenames
  • sharing recipients and forwarding addresses
  • the tenant’s own domains
  • declared-network labels

Declared network prefixes are omitted entirely, because a prefix is not the address of any event and has no alias to take.

City, region, country and network operator are not anonymised. A report whose locations read city_4f2a answers nothing, and they are the point of the geography section. The cover states this, so a reader knows what the label covers.

Nothing in the PDF names the product or the company — not the cover, not the page footers, not the file’s metadata. It is meant to be handed to a client, an auditor or a court as it is. The Markdown export still carries a title and a footer line, since it is normally pasted into a ticket rather than sent onward.