Audit Trail
The Audit Trail tab in HYPR Affirm shows the Affirm events from the HYPR Audit Trail: verification flow configuration changes and the events recorded as each requester moves through a verification. Administrators and security teams use it to trace configuration changes and individual verifications. The tab works like the Audit Trail across HYPR, which is described fully in HYPR Audit Trail.
The Audit Trail view in HYPR 11.3 showing per-workflow lifecycle events and verification flow configuration changes.
Audit Trail Table Columns
The Audit Trail table shows the following columns.
| Column | Description |
|---|---|
| Time | Timestamp of the event |
| Username | The actor who caused the event: an administrator's identifier or, for per-verification events, the requester's identifier (a generated identifier until the requester's login identifier is known) |
| Event | The event identifier (AFFIRM_WORKFLOW_* or AFFIRM_WRITEBACK_*) |
| SubEvent | Additional event detail or path context, where applicable |
| Status | Event outcome: Success or Failure |
| Trace ID | For per-verification events, the workflow ID, which ties the event to the other events of the same verification |
| Logged By | The component that recorded the event (for Affirm events, RELYING_PARTY_SERVER, shortened in the table) |
The page header lists the set of Relying Party applications whose audit data is being shown. Use the date filter and search box (Users, Machine IDs, Session IDs, Device IDs, Trace IDs) to narrow the result set.
What's Captured
The Audit Trail records administrative and lifecycle events covering both Affirm verification flow configuration and per-verification activity. Categories include:
- Workflow lifecycle events —
AFFIRM_WORKFLOW_STARTED,AFFIRM_WORKFLOW_CONSENT, the per-step start and finish events, and the workflow-completion events - Verification flow configuration changes —
AFFIRM_WORKFLOW_CONFIGURATION_CREATED,AFFIRM_WORKFLOW_CONFIGURATION_CHANGEDandAFFIRM_WORKFLOW_CONFIGURATION_REMOVED - Writeback events (
AFFIRM_WRITEBACK_*) — directory image writeback triggered, succeeded, skipped or failed - Escalations and step outcomes —
AFFIRM_WORKFLOW_CHAT_ESCALATIONwhen a failed step or an escalation policy rule sends the requester to a reviewer chat, andAFFIRM_WORKFLOW_STEP_OUTCOME_RESULTwhen too many failed attempts trigger a step's failure outcome
Changes to integrations and feature enablement are recorded in the HYPR Audit Trail, not in this tab.
Changes to code customizations and OIDC settings themselves are not recorded as Audit Trail events. Assigning a customization or an OIDC setting to a verification flow changes the flow's configuration, which is recorded as AFFIRM_WORKFLOW_CONFIGURATION_CHANGED.
Each entry captures the timestamp, the actor (the administrator or the requester), and the operation. Verification flow configuration events also carry the flow's identifier, and created and changed events carry the flow's new configuration.
How It Differs from the Activity Log
The following table compares the two surfaces.
| Surface | Scope | Primary consumers |
|---|---|---|
| Audit Trail (this page) | Per-event stream — verification flow configuration changes and per-workflow lifecycle events | Tenant administrators, security, compliance |
| Activity Log | Per-verification requester outcomes — who attempted, which steps passed, the issued outcome | Support, audit, end-of-flow review |
Both surfaces correlate by Workflow ID for events tied to a specific verification (the Audit Trail shows it as the Trace ID), and by timestamp and actor for configuration-level changes.
Audit Trail Layout in Releases Before 11.3
The following older Audit Trail snapshot records configuration changes as AFFIRM_APPLICATION_CONFIGURATION_CHANGED events. In 11.3, verification flow changes are recorded as AFFIRM_WORKFLOW_CONFIGURATION_CREATED, AFFIRM_WORKFLOW_CONFIGURATION_CHANGED and AFFIRM_WORKFLOW_CONFIGURATION_REMOVED.
The column structure (Time / Username / Event / SubEvent / Status / Trace ID / Logged By) is the same in 11.3 and earlier releases.
Related
- Activity Log — verification attempt records, decisions, and per-step details
- HYPR Audit Trail — global Audit Trail reference across HYPR
- Observability and the Workflow ID — how the audit and activity surfaces correlate