Rich event context
Events can include method, path, status, duration, request and correlation IDs, actor, session, source IP, user agent, lifecycle phase, impact, outcome, retry state, degraded state, trust score, related host or identity, and recommended next action.
Evidence domains
From raw signal to useful explanation
| Signal | Operator-ready interpretation |
|---|---|
| SSO validation failure | Which trust path failed, likely configuration class, correlated attempt, impact, and where to inspect next. |
| Repeated failed login | Source, username or actor context, count and time window, policy result, severity, and containment guidance. |
| SSH or Guacamole failure | Application-to-jump and jump-to-seat evidence, selected relay, blocked port or service, and correct owner. |
| SCIM write error | Lifecycle phase, mapping or directory boundary, retry safety, degraded state, and remediation direction. |
| Database maintenance event | Preview, approval, backup, affected scope, result, and recovery posture. |
Security boundary
- Plaintext passwords are never stored or displayed.
- SCIM bearer tokens, OIDC tokens, SAML assertions, cookies, client secrets, private keys, and database credentials are excluded or redacted.
- Observation is separated from accusation; suspicious activity is described with evidence and confidence.
- Correlation IDs let operators follow one event across authentication, provisioning, directory, host, and database layers.
Designed for remediation
The evidence model answers: what happened, who or what initiated it, which trust or network path was involved, what was affected, whether retry is safe, what evidence should be captured, and what the operator should do next.