Change journal
The change journal records what Nova has written in target systems – with the values before and after. It answers the question “What has Nova changed in this target system?” and is the basis for reverting individual changes.
What an entry contains
The journal records writes of the connectors of all five target system types: accounts created, changed, locked, unlocked and deleted, passwords set, and group memberships and SAP roles added and removed. An entry contains:
- the time, the target system and the object – account, group or role
- the operation, for example “Group assigned” or “Account disabled”
- the affected values “Before” and “After”
- where known, the person who triggered it (“Actor”)
- whether the change can be reverted and whether it has already been reverted
For group memberships and SAP roles, Nova records only effective changes: if Nova finds, for example, that a membership already existed, no entry is created. For SAP, Nova determines the role changes by reading the account's role set before and after writing.
Passwords are not stored in the journal. Nova replaces password attributes such as userPassword, unicodePwd, password or passwordProfile with <redacted> – also in the snapshot of a deleted object.
Where to find the journal
Administrators find the journal under “Monitoring” → “Provisioning Log”. The selection “Backend change” shows journal entries only. Clicking an entry opens the details with system, object, actor and the values “Before” and “After”.
The view shows the most recent entries. Through the programming interface and the AI assistant, the journal can also be searched by target system, operation, account and period.
Reverting changes
For Active Directory, LDAP and Microsoft Entra ID, administrators can revert individual entries. The details then show “Revert”; after the confirmation “Revert change”, Nova performs the inverse operation, for example removing a membership that was added.
Beforehand, Nova checks whether the current state in the target system still matches the recorded after-state. If the object has been changed in some other way since, Nova refuses the revert in the user interface. The revert appears as an entry of its own, and the original entry is marked “Reverted”. Each entry can be reverted only once; Nova rejects a further attempt with “This change was already reverted”.
| Target system | Reversible | Not reversible |
|---|---|---|
| Active Directory, LDAP | account created, changed, locked, unlocked or deleted; group memberships | passwords |
| Entra ID | group memberships | account changes, passwords |
| SAP, Keycloak, SCIM | – | all entries |
Except for account creation, a revert requires a recorded before-value; if Nova could not read it, the entry is not reversible. Entries that cannot be reverted serve traceability only.
Deleted accounts in Active Directory and LDAP
Before deleting an account, Nova stores a snapshot of the entry. The revert recreates the account from it, provided no entry exists under the DN. The new object gets a new unique ID (objectGUID, objectSid or entryUUID); rights bound to the old ID do not pass to the new object. Nova does not restore passwords or attributes maintained by the directory itself. Nova restores group memberships where possible; it records failures as a warning in the “Audit Log”.
What the journal does not record
The journal describes writes that Nova itself performs in target systems. It does not record changes that others make directly in the target system, nor changes within Nova.