Guide · Governance

Reconstruct an incident with the audit log and the evidence chain

Someone tried to share a payslip publicly and was stopped. In the Governance Center you see within a minute who, when, which file and which rule, you export the evidence, and you verify that the log has not been altered.

Canvos · Governance6 min readAudit log · Evidence chain · GDPR

A policy that blocks is nice. Being able to prove what happened is what matters in an audit. Every action that touches your organisation's policy is written by Canvos to a log in which every event carries a sequence number and a hash linked to the previous one: the evidence chain. If a line is later changed or removed, the chain no longer adds up, and you see it. In this guide we follow a real incident: an employee tries to share a payslip containing a national register number publicly. Note: the Governance Center is currently shown in Dutch; the captions below translate every step.

Watch in 60 seconds · From blocked share attempt to chain verification in forty seconds, without sound.

Step by stepSeven steps from incident to evidence

1. The incident: a blocked share attempt 2. Open the Governance Center 3. Choose the Events tab 4. Filter on blocked actions 5. Read the evidence chain 6. Export the evidence 7. Verify the chain

1

The incident: a blocked share attempt

Tom tries to create a public link to a payslip in the Files module. The DLP rule from the national-register-number guide steps in: he sees in red Geblokkeerd: Dit document bevat een rijksregisternummer en mag niet gedeeld worden (blocked: this document contains a national register number and must not be shared), including what was found. The link is not created. Tom has nothing to do; you do, if you want to know what happened.

The share dialog with the red message that sharing is blocked
2

Open the Governance Center

Log in as an administrator and click Governance in the sidebar. If you switched on Notify administrator in step 6 of the DLP guide, you have also received a notification by now.

The Governance Center with the Governance button highlighted
3

Choose the Events tab

Click Gebeurtenissen (events). Every action that touched policy is listed here, with time, user, action, file, policy, result and reason. Changes to the policy itself are included too, so you can always see who changed which rule and when.

The Events tab with the list of all events
4

Filter on blocked actions

Under Resultaat (result) choose Geblokkeerd (blocked). The list now shows only the stopped actions: Tom's share attempt, with the file, the sharing policy and the full reason. With Vanaf (from) and Tot en met (up to) you narrow the period, for example to the month your DPO asked about.

The result filter set to blocked, showing the blocked share attempt
5

Read the evidence chain

In the Keten (chain) column every event shows a sequence number and the start of its hash, for example #66 a3432b4d. That hash is computed over the event's content and the hash of the previous event. One changed character in an older line invalidates every later hash. Every day Canvos also records a signed anchor point.

The blocked event with sequence number and hash in the chain column
6

Export the evidence

Click CSV, JSON or CEF at the top right. CSV suits your accountant or DPO, JSON your own analysis, CEF a SIEM. The export contains the filtered events with their hashes, so the recipient can verify the chain independently.

The export buttons CSV, JSON and CEF
7

Verify the chain

Go to the Compliance tab, section Ketenintegriteit van de gebeurtenissen (chain integrity of the events), and click Keten controleren (verify chain). Canvos recomputes every hash and compares the anchors with their signature. The result states how many events were checked and whether the chain is intact. That is the sentence you show an auditor.

The chain integrity section with the result of the chain verification
What this means for you. You no longer rely on a log file that anyone with server access could edit. The chain makes every change visible, the anchors are signed, and the export lets a third party check it themselves. When the data protection authority, a client or an auditor asks, you have the answer in three clicks: what happened, what was stopped, and the proof that the log is correct.

FAQFrequently asked questions

What exactly is in the log?

Every action that was checked against policy: sharing, download, email, chat and upload, with the result (allowed, warned, blocked), plus every change to the policy itself and system events such as reports and anchor points.

How long is the log kept?

You decide in the Retention policy with Keep audit log. Two years is a sensible minimum; zero means keep forever. Pruned events are replaced by a checkpoint, so the chain stays intact.

What does it mean if the chain is broken?

That an event no longer matches the hash computed over it: the line was changed or something is missing. Canvos shows at which sequence number that happened. Contact your administrator or Canvos.

Can an administrator delete events?

Not without it becoming visible. The log is append-only, and the chain and the signed anchor points make any later intervention demonstrable.

Related guidesRelated guides

Want to try it yourself?

Book a 20-minute demo, or set up your workspace today.

Book a demo