
Getting started: audit a user
The fifth setup task confirms that you can diagnose access issues and see the audit trail. Agilicus AnyX records who accessed what, when, and whether it was allowed; this task makes sure you know where to look.

What this task is for
When a user has a problem, or when you need to demonstrate compliance, you use the audit and diagnostics screens. This task walks through the main places to look so you are ready when you need them.
Where to look
- Authentication audit (Organisation > Authentication Audit): who signed in, when, and whether the sign-in succeeded. See Authentication audit.
- User audits (Access > Audits): everything a user has done across resources. See Access audits.
- Sessions (Organisation > Sessions): active and recent user sessions. See Sessions.
- Application diagnose (Resources > Applications > Diagnose): inspect live request and response traffic for a specific application. See Applications.
- Metrics (Metrics): aggregated usage such as top users and active users. See Metrics.
How to do it
- Open Getting Started > Audit User from the left navigation.
- Follow the guide through the audit screens it lists.
- Practise a real scenario: ask a user to attempt access, then find their sign-in and access events in the audit screens.
- Confirm you can see the reason for any denial (for example a policy rule).
- Mark Audit User complete on the task board.
Diagnostics versus configuration
The audit screens are diagnostics: they are read-only and do not change anything. Use them to observe. Configuration (changing who has access) happens in the permissions and policies screens.
Troubleshooting
- An event is missing: check the audit subsystem health and the audit destinations if you forward logs.
- You cannot see a user’s events: confirm you have permission to view audits for that user.