Reports & Audit Log
Tenaxis keeps a detailed recorded history of governance actions - every action taken by admins, every automated job, every member change, every policy applied. You can view this in the Audit Log and download structured reports for compliance purposes.
Reports
Go to Reports in the left sidebar to access downloadable compliance reports. All reports are generated as CSV files that you can open in Excel, Google Sheets, or import into your compliance tools.
Available Reports
1. Site Inventory Report
What it contains:
- All SharePoint sites managed by Tenaxis
- For each site: name, status, lifecycle status, risk score, M365 group owner/member counts and legacy unverified visitor record counts, template applied, security policy applied, source (provisioned or imported), creation date, last activity date
Use for:
- Providing auditors with the sites managed by Tenaxis; consult estate coverage for unmanaged sites
- Identifying sites without policies applied (compliance gap)
- Finding high-risk sites for remediation planning
- Regular governance reporting to leadership
How to download:
- Go to Reports
- Click Download next to "Site Inventory"
- A CSV file downloads immediately
2. Access Report
AccessScope distinguishes M365 group roles from unsupported visitor access.
CACHED_OBSERVATION is stored group-role data, not a fresh Microsoft verification.
LEGACY_VISITOR rows carry UNSUPPORTED_VISITOR_ACCESS and
HISTORICAL_UNVERIFIED: they do not prove current access, removal or expiry.
Zero legacy visitor records does not mean there are no visitors.
The evidence package uses legacy-visitor-observations.csv for these records.
Its RecordedExpiresAt, RecordedRenewalSentAt and RecordedRenewedAt columns
are historical values, not proof that access expired or was renewed in Microsoft.
Inspect SharePoint directly for visitor access and other access paths.
What it contains:
- Cached M365 group owner/member observations plus retained legacy visitor records
- For each row: site name, user display name, user UPN (email), recorded role (OWNER/MEMBER/LEGACY_VISITOR), AccessScope and ObservationStatus
- Includes both internal users and external guests (#EXT# accounts)
Use for:
- Reviewing recorded group roles, with additional SharePoint checks for other access paths
- Identifying over-privileged users (e.g., too many OWNERs)
- Identifying group roles that require further access review
- Quarterly access control reports
How to download:
- Go to Reports
- Click Download next to "Access Report"
- A CSV file downloads immediately
3. Audit Log Export
What it contains:
- A complete log of all admin actions taken in Tenaxis
- For each entry: timestamp, actor (admin email or "System"), action taken (human-readable description), target (site/user/policy name), whether it succeeded or failed, error details if failed
Use for:
- Security incident investigations ("who changed this site's policy on Tuesday?")
- Proving to auditors that access changes were authorized and logged
- Compliance framework requirements for admin action trails
- Internal IT review meetings
How to download with a date range:
- Go to Reports
- Find "Audit Log Export"
- Select a Start Date and End Date
- Click Download
You'll get all audit entries within that date range as a CSV.
Audit Log (In-App View)
The Audit page in the left sidebar gives you a real-time, paginated view of all audit log entries directly in the Tenaxis interface - no download required.
What You See
Each entry shows:
| Column | What it means |
|---|---|
| Timestamp | Exact date and time of the action |
| Actor | Who performed the action (admin name/email, or "System" for automated actions) |
| Action | A human-readable description of what happened |
| Target | The site, user, policy, or other object the action was applied to |
| Status | Whether the action succeeded ✓ or failed ✗ |
| Error | If failed, what went wrong |
What Gets Logged
Every significant action in Tenaxis is logged:
Site Actions:
- Site provisioned (including which admin approved and the template used)
- Site archived/deleted
- Security policy applied to a site
- Site settings updated
- Site synced from Microsoft 365
User/Access Actions:
- Member added to a site (including their role)
- Member removed from a site
- Site ownership changed
- Admin added to workspace
- Admin removed from workspace
- Admin role changed
Request Actions:
- Site request submitted (by user)
- Site request approved (by which admin)
- Site request rejected (by which admin, with rejection note)
Access Review Actions:
- Review cycle created
- Owner accessed review link
- Each KEEP / REMOVE decision
- Member removed as a result of a review
- Review completed or expired
Lifecycle Actions:
- Site flagged as renewal pending
- Renewal confirmation received (owner clicked link)
- Site escalated due to no response
Offboarding Actions:
- Disabled user identified
- User removed from site(s) via offboarding
Settings Changes:
- Lifecycle settings updated
- Alert thresholds changed
- Naming policy updated
- Access review configuration changed
- Webhook added, updated, or deleted
System Actions:
- Nightly sync results
- Background jobs (provisioning, template application, etc.)
- Webhook delivery attempts
Pagination
The audit log can contain thousands of entries for active organizations. Use the Next / Previous buttons to navigate through pages. Each page shows 100 entries, ordered from newest to oldest.
Using Reports for Compliance Audits
When an auditor asks for documentation of your SharePoint governance, here's what to provide:
ISO 27001 / SOC 2
- Site Inventory - Proves you know what data stores exist
- Access Report - Provides cached group-role observations and clearly marked unverified history
- Audit Log Export (full year) - Proves access changes are logged and reviewed
GDPR
- Access Report - Supports a scoped group-role review; does not establish effective access to personal data
- Audit Log Export - Shows when access was granted/revoked and by whom
SOX (if applicable)
- Access Report - Supports a scoped review of group roles for financial workspaces
- Audit Log Export - Proves segregation of duties and access reviews occurred
General Internal Audit
- Site Inventory - Management overview of the SharePoint estate
- Access Report - Periodic access control review
- Audit Log Export (date range) - Review of specific incidents or time periods
Tips for Auditors
The reports are designed to be self-explanatory, but here are some tips:
- The Access Report contains scoped observations; it does not answer every "who can access what" question
- The Audit Log is the single most useful document for "how did this happen / who did this" questions
- All timestamps in Tenaxis are stored and exported in UTC - adjust for your local time zone when reviewing
- The "System" actor in the audit log means the action was performed by an automated Tenaxis job (e.g., nightly sync, lifecycle check), not a human admin
Offboarding CSV evidence types
offboarding-log.csv distinguishes four types of evidence:
| Type | Meaning |
|---|---|
CACHED_DISABLED_ACCOUNT_ROLE | Stored group role for an account observed as disabled; not a fresh access check. |
REMOVAL_RECORDED_UNVERIFIED | A removal event without qualifying readback evidence, including legacy automatic-removal events. |
REMOVAL_FAILED | A failed removal event; see Error and the original AuditDetails. |
REMOVAL_VERIFIED | A successful OFFBOARDING_MEMBER_REMOVED event with the explicit MICROSOFT_ROLE_READBACK marker. |
VerificationStatus is MICROSOFT_ROLE_READBACK only for the last type; otherwise
it is NOT_VERIFIED. All rows concern M365 group roles. Historical verification
does not prove current access or complete offboarding across all SharePoint
access paths. A failure does not by itself establish the resulting Microsoft state.
AuditEventId, AuditAction, AuditActor, timestamps and original AuditDetails
allow investigation. SiteId and UPN are separate columns. Missing historical
identity fields remain blank rather than being inferred from a site identifier.
AccountCheckedAt describes the stored account observation, not removal time.
CSV consumers must use these headers; the old DISABLED_ACTIVE/REMOVED labels
and column layout have been replaced.