๐ก๏ธ Audit Policy
๐ค Who it's for: Security Administrators / Compliance Officers
โฑ๏ธ Read time: ~5 minutes
๐ก In one line: Who did what and when โ everything is traceable.
YingClaw has a built-in operation auditing system that records all critical actions with flexible policy configuration for enterprise security auditing and compliance.
Featuresโ
| Feature | Description |
|---|---|
| ๐ Operation Audit | Record user actions, system events, tool invocations, and more |
| โ๏ธ Policy Configuration | Custom audit rules with flexible scope and alert conditions |
| ๐ Audit Status | Real-time view of audit system status and toggle |
| ๐ Compliance Reports | Exportable audit logs for regulatory and internal reviews |
Audit Event Typesโ
YingClaw's audit system covers the following event types:
| Event Type | Description |
|---|---|
| User Login/Logout | Records all login attempts and results |
| Agent Start/End | Tracks AI Agent creation and destruction |
| Tool Invocation | Records shell commands, file operations, network requests |
| Config Changes | Tracks all configuration file modifications |
| Channel Messages | Records messages sent and received across platforms |
How to Useโ
View Audit Statusโ
Log into the YingClaw Web Console and click "Audit Policy" in the left navigation.
On the "Status" tab you can view:
- Whether the audit system is enabled
- Current audit event statistics
- System health status
Configure Audit Policyโ
Switch to the "Policy" tab to customize:
- Audit toggle (global enable/disable)
- Event filtering rules (select which event types to record)
- Alert threshold configuration
Audit Logsโ
Each audit event record contains:
- Timestamp
- Actor identity
- Action type
- Action details
- Result
Notesโ
- โ ๏ธ A disclaimer must be accepted on first visit to the audit page
- ๐ Audit policy configuration requires administrator privileges
- ๐ Audit logs consume storage โ schedule regular archiving
Next Stepsโ
Learn about ๐ Updates to keep your system current.