Falaah Falaah AI

Audit Logs & Security

View comprehensive audit logs of every action in your Muin organization — who did what, when, and what changed. Essential for compliance and security.

Muin maintains comprehensive audit logs of all activity in your organization. Essential for security monitoring, compliance requirements, and investigating issues.

Audit Logging Overview

Muin logs all significant actions:

  • Who performed the action
  • What action was taken
  • When it occurred
  • Where (IP address, device)
  • What changed (before/after values)

What’s Logged

User Actions

Action Type Examples
Authentication Login, logout, password change
Document Upload, view, edit, delete, download
Data Create, update, delete records
Approval Approve, reject, delegate
Settings Configuration changes
Team Invite, remove, role change

System Events

Event Type Examples
Processing Document processed, extraction complete
Workflow Workflow triggered, action executed
Agent Agent run started, completed, failed
Integration Sync started, API call, webhook

Security Events

Event Type Examples
Access Failed login, suspicious activity
Permissions Access denied, role changed
Data Sensitive data accessed, exported

Viewing Audit Logs

Accessing Logs

  1. Navigate to SettingsSecurityAudit Logs
  2. View recent activity
  3. Use filters to narrow results

Log Entry Details

Each entry shows:

  • Timestamp - When it occurred
  • User - Who performed action
  • Action - What was done
  • Resource - What was affected
  • Details - Additional context
  • IP Address - Where request originated

Example Entry

2026-01-15 14:32:17 UTC
User: jane.smith@company.com
Action: Document Approved
Resource: Invoice #INV-2024-0892
Details: Approval for payment, amount $4,567.00
IP: 192.168.1.100
Session: Browser, Chrome on macOS

Filter Options

Filter Options
Date Range Custom range, presets
User Specific user, all users
Action Type Authentication, document, etc.
Resource Type Documents, users, settings
Status Success, failure

Search logs by:

  • User email
  • Resource name or ID
  • Action keyword
  • IP address

Saved Filters

Save frequently used filters:

  1. Configure your filters
  2. Click Save Filter
  3. Name your filter
  4. Access later from saved filters

Audit Reports

Standard Reports

Report Contents
User Activity All actions by specific user
Document Access Who accessed what documents
Login History Authentication events
Configuration Changes Settings modifications
Approval History All approval actions

Running Reports

  1. Navigate to Audit LogsReports
  2. Select report type
  3. Set date range and filters
  4. Generate report
  5. Export as PDF or CSV

Scheduled Reports

Automate compliance reporting:

  1. Configure report parameters
  2. Set schedule (daily, weekly, monthly)
  3. Add email recipients
  4. Reports delivered automatically

Export for Compliance

Export Formats

Format Use Case
CSV Analysis in spreadsheets
JSON Integration with SIEM
PDF Documentation and audits

Bulk Export

For large exports:

  1. Set date range and filters
  2. Click Export All
  3. Choose format
  4. Export runs in background
  5. Download when ready

Compliance Packages

Generate audit packages for:

  • SOC 2 audits
  • GDPR requests
  • Internal audits
  • Security reviews

Retention Policy

Default Retention

  • Standard activity: 1 year
  • Security events: 2 years
  • Compliance-related: 7 years

Configuring Retention

Enterprise customers can configure:

  1. Navigate to SettingsSecurityData Retention
  2. Set retention period by log type
  3. Configure archive policy
  4. Set deletion policy

Archive Access

Archived logs:

  • Moved to cold storage after active period
  • Accessible via special request
  • May take longer to retrieve
  • Full fidelity maintained

Security Monitoring

Real-Time Alerts

Set up alerts for security events:

  1. Navigate to SettingsSecurityAlerts
  2. Configure alert rules:
    • Failed login attempts (>3)
    • Login from new location
    • Sensitive data export
    • Permission changes
  3. Set notification method
  4. Enable alerts

Suspicious Activity

Muin flags potentially suspicious activity:

  • Multiple failed logins
  • Unusual access patterns
  • Large data exports
  • Access from blocked locations

Responding to Alerts

When alerted:

  1. Review the activity
  2. Check if legitimate
  3. Take action if needed:
    • Reset password
    • Disable account
    • Investigate further

Access Control for Logs

Who Can View Logs

Role Access
Owner All logs
Admin All logs except billing
Manager Logs for their team only
Member Their own activity only

Protecting Audit Integrity

  • Logs cannot be modified or deleted by users
  • Log system isolated from main application
  • Configurable retention policies per log type

Best Practices

For Security

  1. Review regularly - Check logs at least weekly
  2. Set up alerts - Don’t rely on manual review
  3. Investigate anomalies - Don’t ignore unusual activity
  4. Limit access - Only necessary people view logs

For Compliance

  1. Know requirements - Understand what you need to log
  2. Set retention appropriately - Meet regulatory minimums
  3. Regular exports - Don’t rely only on Muin storage
  4. Test retrieval - Ensure you can get logs when needed

For Troubleshooting

  1. Correlate events - Look at related entries
  2. Check timestamps - Understand sequence of events
  3. Look at context - Before and after the issue
  4. Export for deep analysis - Use external tools if needed

Troubleshooting

Can’t Find Expected Log Entry

  1. Verify the action actually occurred
  2. Check your date range filter
  3. Try broader filters first
  4. Check if action type is logged
  5. Allow for slight timestamp differences

Log Export Issues

  1. Reduce date range for large exports
  2. Try different export format
  3. Check export isn’t still processing
  4. Contact support for very large exports

Access Denied to Logs

  1. Verify your role has log access
  2. Check with admin for permissions
  3. Some logs may be restricted by role

Next Steps