Logs
Nova keeps three records. Each answers a question of its own:
| Record | Answers |
|---|---|
| “Audit Log” | Who did what in Nova? |
| “Provisioning Log” | What did Nova intend and execute for each identity? |
| Change journal | What did Nova actually change in the target system? |
One chain, one correlation ID
A shared correlation ID links the entries that belong together:
Access request → approval → assignment → provisioning run → change in the target system → confirmation
This way, an access request can be followed into the target system – and, conversely, a change in the target system back to its request.
What Nova records
- Identities and assignments: every change to identities and to their entitlements and business roles.
- Accounts: every change to accounts, including password resets and locks. Nova files these entries under the affected identity.
- Catalogue and organisation: changes to entitlements, business roles, organisational units and approval workflows.
- Configuration: changes to target systems and settings, each with the values before and after; secrets masked.
- Sign-ins: successful and failed sign-ins to Nova – see Signing in to Nova.
- AI assistants: actions of an AI assistant, marked with the assistant – see AI guardrails.
Every entry names its actor – who or what initiated the action: a person, a job or an AI assistant.
Unalterable and permanent
- Log entries are append-only. No function in Nova changes or deletes them, and the database user Nova runs with has no right to do so.
- Nova stores timestamps with their time zone and shows them in local time.
- When an identity is deleted, its log entries are kept.
- Secrets such as passwords, client secrets, tokens and keys never appear in any log.
Who can see the logs
Only authorised roles can see the logs: administrators and auditors. The logs are found under “Monitoring” → “Audit Log” and “Provisioning Log”; the change journal is part of the “Provisioning Log”. Personal log views show each identity only its own entries.
How auditors use the logs is shown in the Auditor guide.