Skip to main content
Version: 11.3.0

Audit Trail

The Audit Trail tab in HYPR Affirm shows the Affirm events from the HYPR Audit Trail: verification flow configuration changes and the events recorded as each requester moves through a verification. Administrators and security teams use it to trace configuration changes and individual verifications. The tab works like the Audit Trail across HYPR, which is described fully in HYPR Audit Trail.

Audit Trail table with Affirm workflow consent, started and configuration changed events, each with its status, trace ID and logging component

The Audit Trail view in HYPR 11.3 showing per-workflow lifecycle events and verification flow configuration changes.

Audit Trail Table Columns​

The Audit Trail table shows the following columns.

ColumnDescription
TimeTimestamp of the event
UsernameThe actor who caused the event: an administrator's identifier or, for per-verification events, the requester's identifier (a generated identifier until the requester's login identifier is known)
EventThe event identifier (AFFIRM_WORKFLOW_* or AFFIRM_WRITEBACK_*)
SubEventAdditional event detail or path context, where applicable
StatusEvent outcome: Success or Failure
Trace IDFor per-verification events, the workflow ID, which ties the event to the other events of the same verification
Logged ByThe component that recorded the event (for Affirm events, RELYING_PARTY_SERVER, shortened in the table)

The page header lists the set of Relying Party applications whose audit data is being shown. Use the date filter and search box (Users, Machine IDs, Session IDs, Device IDs, Trace IDs) to narrow the result set.

What's Captured​

The Audit Trail records administrative and lifecycle events covering both Affirm verification flow configuration and per-verification activity. Categories include:

  • Workflow lifecycle events — AFFIRM_WORKFLOW_STARTED, AFFIRM_WORKFLOW_CONSENT, the per-step start and finish events, and the workflow-completion events
  • Verification flow configuration changes — AFFIRM_WORKFLOW_CONFIGURATION_CREATED, AFFIRM_WORKFLOW_CONFIGURATION_CHANGED and AFFIRM_WORKFLOW_CONFIGURATION_REMOVED
  • Writeback events (AFFIRM_WRITEBACK_*) — directory image writeback triggered, succeeded, skipped or failed
  • Escalations and step outcomes — AFFIRM_WORKFLOW_CHAT_ESCALATION when a failed step or an escalation policy rule sends the requester to a reviewer chat, and AFFIRM_WORKFLOW_STEP_OUTCOME_RESULT when too many failed attempts trigger a step's failure outcome

Changes to integrations and feature enablement are recorded in the HYPR Audit Trail, not in this tab.

Changes to code customizations and OIDC settings themselves are not recorded as Audit Trail events. Assigning a customization or an OIDC setting to a verification flow changes the flow's configuration, which is recorded as AFFIRM_WORKFLOW_CONFIGURATION_CHANGED.

Each entry captures the timestamp, the actor (the administrator or the requester), and the operation. Verification flow configuration events also carry the flow's identifier, and created and changed events carry the flow's new configuration.

How It Differs from the Activity Log​

The following table compares the two surfaces.

SurfaceScopePrimary consumers
Audit Trail (this page)Per-event stream — verification flow configuration changes and per-workflow lifecycle eventsTenant administrators, security, compliance
Activity LogPer-verification requester outcomes — who attempted, which steps passed, the issued outcomeSupport, audit, end-of-flow review

Both surfaces correlate by Workflow ID for events tied to a specific verification (the Audit Trail shows it as the Trace ID), and by timestamp and actor for configuration-level changes.

Audit Trail Layout in Releases Before 11.3​

The following older Audit Trail snapshot records configuration changes as AFFIRM_APPLICATION_CONFIGURATION_CHANGED events. In 11.3, verification flow changes are recorded as AFFIRM_WORKFLOW_CONFIGURATION_CREATED, AFFIRM_WORKFLOW_CONFIGURATION_CHANGED and AFFIRM_WORKFLOW_CONFIGURATION_REMOVED.

Earlier Audit Trail layout listing Affirm application configuration changed events with Time, Username, Event, SubEvent, Status, Trace ID and Logged By columns

The column structure (Time / Username / Event / SubEvent / Status / Trace ID / Logged By) is the same in 11.3 and earlier releases.