Understanding Performed By

Estimated reading: 1 minute 4 views

Overview

Performed By identifies the user account associated with an audit event.

What this feature does

It shows which staff member, admin, or system user performed the recorded action where user context is available.

Why it is useful

  • It creates accountability.
  • It helps investigate sensitive changes.
  • It helps managers understand team activity and responsibility.

Who should read this?

RISE Admin, System Owner, Security Officer, Team Manager.

Where to find it

Performed By appears in Activity Log and related reports or details.

How to use it

  1. Open Activity Log.
  2. Use the user filter or Performed By column.
  3. Review actions linked to a specific user.
  4. Compare with Auth Log if the event seems suspicious.

Example workflow

If a contract was updated unexpectedly, the admin checks the Performed By value and then opens Auth Log to confirm the user’s login activity around the same time.

Common mistakes

  • Assuming user identity alone proves intent. Always review context, timestamp, IP address, and related events.
  • Ignoring actions performed by automated or system processes.

Related articles

  • Auth Log Overview
  • Investigating Suspicious Login Activity
  • Session Timeline
Share this Doc

Understanding Performed By

Or copy link

CONTENTS
Shopping Basket