Evose
GovernDesktop

Desktop · Audit Events

User behavior audit on the desktop client · Compliance and forensics

User behavior auditing on the desktop client. Events are tamper-proof, retained long-term, suitable for compliance and forensics.

Event Coverage

CategoryIncludes
AuthenticationLogin success / failure · Multi-device login · Active logout · Lock screen
Data accessViewing Agent / Workflow / KB / Documents
File operationsUpload / download / delete / export
Policy hitsOperations blocked by policy (e.g. attempted copy was prevented)
Device fingerprintDevice ID / IP / geolocation / client version
Session eventsSession timeout / forced logout

Query Capabilities

DimensionExample
Time rangeLast 24 hours / 7 days / custom
UserSingle user / department / role
Event typeAuthentication only / files only / policy hits only
StatusSuccess / failure / blocked

Export

CSV / JSON export supported, can integrate with external SIEM (Splunk / ELK / Datadog).

GET /api/audit/events?start=2026-05-01&end=2026-05-08&format=json

Alert Rules (Planned)

Rule exampleTrigger
Same user has ≥ 5 login failures in 1 hourNotify admin
Single user downloads > 10 files in one sessionNotify + secondary verification
Login from unusual geolocationNotify + force MFA

Retention

ScenarioRecommended retention
General SaaS90 days
Internal compliance1 year
MLPS Level 3 / Finance / Healthcare7 years

In Private, customers can customize per compliance.

Compliance Mapping

ComplianceCoverage
MLPSRequired: traceable audit logs
GDPRData access traceability; supports data subject rights
ISO 27001A.12.4 logging and monitoring control family

Next Steps

On this page