Skip to content

Audit actions

Each call the policies decide asks for one action. Its access event records that action. An application never sees a policy, a rule or a classification. It sees only the decision and, on allow, the action the access event carries.

CallAction
objects.openView, Access Record or Download File, as the action option says
objects.openFieldView Field
opened.requestCopy, Print, Download File or Access Record
folders.listView, on the folder index
folders.searchQuery Records, one per index opened
objects.save, objects.create, objects.acceptPending, offline.saveDraftsSave
domains.share, domains.shareRecord, domains.makeOwner, domains.createShare Record
objects.delete, domains.delete, domains.shredDelete
domains.restoreRestore
The offline lease the SDK renewsLease
recovery.askRecover
people.revokeRevoke
people.offboardOffboard
people.changeRoleChange Role
policies.submitSubmit Policy
policies.approveApprove Policy
evidence.exportExport

A call that the policies decide but that has no named action, such as people.mapGroup or policies.withdraw, still records one decision and one access event.