--- title: "Log Profiles & Audit Logging" description: "Compliance audit logging, telemetry event tracking, security surveillance of supervisory eavesdropping, and CRUD operation logging per module." --- ## 📖 Introduction The **Log Profiles** module delivers forensic security and compliance audit logging across the Switchboard subsystem. In regulated enterprise environments (e.g., healthcare, financial services, and customer care centers), administrators must maintain an immutable record of operator activities—particularly sensitive supervisory telephony actions such as silent eavesdropping, whisper coaching, and line barging. Log Profiles define exactly which operational events (Create, Read, Update, Delete, and Action) are captured in the platform's tamper-evident audit logs (`ss_switchboard.audit_logs`). ![Log Profiles Management](/screenshots/apps/switchboard/log-profiles.png) --- ## 📋 System Profiles | Profile Name | Status | Intended Scope | Logging Intensity | | :--- | :--- | :--- | :--- | | **Default Profile** | Active / Default | Standard operator workstation operations. | Captures modifications, deletions, authentication events, and call transfers. | | **Supervisor Audit** | Active | Supervisory, quality assurance, and managerial accounts. | High-fidelity logging capturing every `Spy`, `Whisper`, `Barge`, and queue intervention. | --- ## 🔍 Module Audit Grid & Event Types When configuring a Log Profile, administrators enable specific audit triggers for each subsystem module: | Module Identifier | Functional Area | Key Audited Telephony & Management Events | | :--- | :--- | :--- | | `auth` | **Authentication** | Operator login, logout, session expiration, SSO token validation, and failed attempts. | | `extensions` | **Extensions** | Silent listening (`spy`), whisper coaching, barge-in calls, and extension dial actions. | | `queues` | **Queues** | Agent pause/resume cause codes, queue member logins, and queue call interceptions. | | `parking` | **Parking Lots** | Call parking origins, parking retrieval events, and parking timeout drops. | | `conferences` | **Conferences** | Room lock/unlock, attendee kicks, mute/unmute commands, and floor control. | | `active_calls` | **Active Calls** | Channel hangup overrides, line hold/resume, attended transfers, and blind transfers. | | `layouts` | **Layouts** | Grid repositioning, layout creation, widget additions, and global layout publication. | | `log_profiles` | **Log Profiles** | Audit trail configuration changes and profile modifications. | | `roles` | **Roles & Permissions** | Privilege escalations, RBAC assignment adjustments, and permission level edits. | | `pause_profiles` | **Pause Profiles** | Creation, reordering, or alteration of call center agent pause reason codes. | | `flag_profiles` | **Flag Profiles** | Visual call tag definitions and color classification rules. | | `branding` | **Branding** | White-label logo uploads, favicon replacements, and login welcome text edits. | | `webrtc` | **WebRTC Settings** | Modifications to STUN, TURN, or ICE timeout settings. | | `connection` | **Connection Settings**| Switchboard node mode toggles (Local vs Remote) and API endpoint updates. | --- ## 🎯 Audit Action Types Each module supports five distinct event classifications: | Audit Action | Pill Indicator | Description & Forensic Purpose | | :--- | :--- | :--- | | **Create** (`log_create`) | `[ + Create ]` (Green) | Emits an audit entry when new records, layouts, or profiles are provisioned. | | **Read** (`log_read`) | `[ 👁 Read ]` (Blue) | Logs read operations and sensitive data inspections. | | **Update** (`log_update`) | `[ ✎ Update ]` (Amber) | Logs field-level changes with previous and updated state diffs. | | **Delete** (`log_delete`) | `[ ✕ Delete ]` (Red) | Records record deletions with operator ID, IP address, and timestamp. | | **Action** (`log_action`) | `[ ⚡ Action ]` (Emerald) | Crucial for telephony: logs call transfers, eavesdrops, whisper coaches, and barge-ins. | ```text [ Operator: alexander (1001) ] ──⚡ Action──> [ Eavesdrop on Ext 1045 ] ──> [ ss_switchboard.audit_logs ] ``` --- ## 📊 Audit Record Attributes Audit log entries emitted by configured Log Profiles contain comprehensive metadata: - **Timestamp**: High-precision UTC timestamp (`YYYY-MM-DD HH:MM:SS.sssZ`). - **User Identity**: Account ID, username, and assigned role. - **Client IP & User-Agent**: Originating browser IP address, operating system, and browser engine. - **Tenant Scope**: Invariant numerical `tenant_id` and `domain_id`. - **Target Resource**: The affected record ID, extension number, or telephony channel UUID. - **Payload / Changes**: Structured JSON payload detailing modified values and parameters. > [!IMPORTANT] > To comply with privacy regulations (such as HIPAA, GDPR, and PCI-DSS), audit logs do not store audio streams. Only the metadata timestamp, supervisory operator ID, and target extension channel UUID are recorded.