The Audit and Security subsystem provides a single point where all Activate Jobs are logged and tracked.
Security
Activate Security is based upon Activate Roles. Activate Roles leverage the membership information within your Active Directory environment but is not relient upon Delegation with Active Directory.
The Activate Server uses 'elevated privledge' to perform it's tasks. This allows the Activate Server to perform actions on behalf of users that they would not normally have the rights to do themselves. Activate provides the ability to delegate, audit and secure these tasks in a consistent and secure manner.
Activate's Role and Security subsystem allows flexibility in delegation that far exceeds what is possible within Active Directory using native security. For example, you can delegate the right for 'Managers' to add services to their 'Direct Reports' by changing a single Access Point.
Activate does not require a huge investment in rearranging your Active Directory environment for delegation but provides a simple yet powerful way of defining the delegation rules.
Changes to the delegation rules can normally be performed in a matter of minutes rather than requiring massive redesign of your Active Directory environment.
Audit Logs
All Audit logs are kept with the Activate Database. Built-in Activate reports allow this information to be viewed, or any SQL reporting tool can be used to create customized reports as required.
There are three major types of Audit logs kept within the Activate System.
- Job Approval Logs
The Job approval logs track all approvals and manual steps during the execution of an Activate Job. This information includes information like who approved a request, when they did it and any notes they made when approving the request.
- Job Audit Logs
Audit logs are maintained for each job. These logs contain a detailed view of the execution of the job. These logs are useful for tracking errors and determining why a failure may have occured.
- User Logs
Activate tracks all changes to user accounts in a seperate log. This allows an easy trace of the changes that have been made to a particular users account. The log contains information like who requested the change, when it was done and what was changed.