The audit section
Audit is the panel’s memory. Five tabs, one question each.
Sign-in events
Section titled “Sign-in events”Every sign-in that reached Dynacop verification: person, Windows account, resource, session (type + source IP + location), and the result. Panel sign-ins appear in the same stream with a Dynacop Panel badge — one unified identity, one unified log.
Result vocabulary:
| Result | Meaning |
|---|---|
| Allow | Verified with the second factor |
| Allow (exempt) | Allowed without factor verification — marked honestly |
| Enroll | Person was sent to enrollment |
| Deny | Refused (reason shown — see troubleshooting) |
| Deny (code) | Wrong second-factor code |
Admin actions
Section titled “Admin actions”Who changed what in the panel: invitations, role changes, policy edits, access grants/removals, customer operations, manual blocks, renames… Each entry shows the actor, the target, details, and the time. This is your workspace’s change history.
Agent updates
Section titled “Agent updates”The fleet’s update trail — per machine: previous version → new version and the result (success, failed, downgrade blocked, offered). See automatic updates.
Attacks
Section titled “Attacks”The Shield feed — attacking source IPs, attempts, tried usernames, service attribution, and block status, with manual block/unblock. Covered in depth in attacks and blocks.
Sign-in sources and attack sources on a world map for the last 1 / 7 / 30 days, with an attacks toggle. Geo-resolution is done on Dynacop’s own servers — IPs are never sent to a third-party service.