Skip to content

Enterprise-ready playbook

Ship audit logs and log streaming

Updated 2026-07-19

Why enterprises demand it

  • Security reviews and compliance (SOC 2, ISO, HIPAA) require audit trails
  • Enterprises want identity events in their own SIEM, not just your UI
  • Incident investigation depends on complete, tenant-scoped logs

How to implement

  1. 1Log authentication, authorization, and admin events with actor, target, and context
  2. 2Scope every event to its Organization
  3. 3Make logs tamper-evident and retain them per policy
  4. 4Offer export (API/CSV) and streaming to a SIEM (webhook or log stream)

Standards

  • SIEM integration (webhook / log stream)
  • Retention aligned to SOC 2 / ISO

Pitfalls

Logging without tenant scope

Enterprises need only their events; cross-tenant logs are a leak and a non-starter.

Sparse events

Logs without actor, target, IP, and outcome are useless in an investigation.

No export path

Security teams will not accept logs trapped in your dashboard.

Build checklist

  • Auth, authz, and admin events logged with full context
  • Every event scoped to the tenant
  • Tamper-evident with a retention policy
  • Export and SIEM streaming available

What to require of a platform

  • Per-tenant audit logs
  • Log export and SIEM streaming
  • Sufficient event coverage and context

Go deeper

Build it: blueprints

FAQ

What events belong in a CIAM audit log?
Authentication, authorization, and administrative actions, each with actor, target, IP, outcome, and timestamp, scoped to the tenant. Sparse logs without that context are useless in an investigation.
Do enterprises need log streaming, or is a dashboard enough?
Increasingly they need streaming. Security teams want identity events in their own SIEM for correlation and retention, so offer export and streaming (webhook or log stream), not just an in-app view.