Audit actions
Each call the policies decide asks for one action. Its access event records that action. An application never sees a policy, a rule or a classification. It sees only the decision and, on allow, the action the access event carries.
| Call | Action |
|---|---|
objects.open | View, Access Record or Download File, as the action option says |
objects.openField | View Field |
opened.request | Copy, Print, Download File or Access Record |
folders.list | View, on the folder index |
folders.search | Query Records, one per index opened |
objects.save, objects.create, objects.acceptPending, offline.saveDrafts | Save |
domains.share, domains.shareRecord, domains.makeOwner, domains.create | Share Record |
objects.delete, domains.delete, domains.shred | Delete |
domains.restore | Restore |
| The offline lease the SDK renews | Lease |
recovery.ask | Recover |
people.revoke | Revoke |
people.offboard | Offboard |
people.changeRole | Change Role |
policies.submit | Submit Policy |
policies.approve | Approve Policy |
evidence.export | Export |
A call that the policies decide but that has no named action, such as people.mapGroup or policies.withdraw, still records one decision and one access event.