Auditor guide
This page maps typical audit questions to the places in Nova that answer them. They build on the three logs and the correlation ID that links their entries.
Starting point: an identity's history
An identity's “History” shows the whole chain as a timeline: access request → approval → assignment → provisioning run → change in the target system → confirmation. Questions about a single person start here. Questions about many identities are answered by reports under “Reporting” and their exports.
Exporting the audit log
The filtered “Audit Log” can be exported as CSV or JSON.
Typical questions
Who has access to X – and since when?
- Where: a report under “Reporting”, as an export.
- Evidence: all identities with a valid assignment of the entitlement or business role, each with the start and end of validity and the time of the last confirmation in the target system.
Why does person Y hold entitlement Z?
- Where: the identity's “History”.
- Evidence: who requested the entitlement, who approved it and when, when Nova provisioned it and when Nova confirmed it in the target system.
Which leavers still have an active account anywhere?
- Where: a report under “Reporting” on the accounts of terminated identities.
- Evidence: for each account, the status last read in the target system with the time of that read. How Nova locks accounts when an identity leaves is described under Accounts and passwords.
Which accounts in a target system belong to no one?
- Where: the target system's orphaned accounts – see Accounts and passwords.
- Evidence: all accounts that exist in the target system but belong to no identity.
What changed in SAP in a given period – and who triggered it?
- Where: the change journal, narrowed down to the SAP system and the period.
- Evidence: every change Nova wrote there, with the values before and after and the actor; through the correlation ID, also the related run and access request. Changes that others made directly in SAP are shown by reconciliation.
Which SoD conflicts exist – and who accepted which exception?
- Where: “Compliance” → “Risk Analysis”, “SoD Violations” register – see Segregation of duties (SoD).
- Evidence: open, accepted and mitigated violations; for accepted and mitigated ones, the person who decided and their justification. Nova also records overrides on access requests with the person and justification.
What is the evidence for a recertification?
- Where: “Compliance” → “Recertification”, then “Download CSV” – see Recertification.
- Evidence: for each item, the reviewer, decision, reason, time, flags and revocation status.