Finlay.worksBareBones Ticketing manual

Audit Events

For administrators and auditors. Audit Administration is at /admin/audit and needs SystemAdmin plus step-up.

Every name on this page is a verbatim action string used by the product. Type them into the exact-action filter as written. They are case-sensitive.

Why you need this list

The action picker in Audit Administration is built from actions already recorded within the time window you have selected, not from your whole database. An action that has never occurred on your installation, or that occurred outside the selected window, does not appear in the picker at all. To search for one, type it.

Audit and export

Action
AuditExported
RedactionRegisterViewed
RedactionRegisterExported

Tenant and configuration

Action
TenantCreated, TenantUpdated
WebSecurityAdminConfigCreated, WebSecurityAdminConfigUpdated
StorageContinuityAdminConfigCreated, StorageContinuityAdminConfigUpdated
HttpsCertificateAdminConfigCreated, HttpsCertificateAdminConfigUpdated

Sign-in and session

Action
LoginSucceeded, LoginFailed, LoginRateLimited, Logout
ExternalParticipantAuthenticated, ExternalParticipantLoginRateLimited, ExternalParticipantLogout

Customer Portal SSO sign-out records plain Logout, with the actor source set to CustomerPortalSso.

Step-up and system protection

Action
AdminStepUpVerificationSucceeded, AdminStepUpVerificationFailed
SystemAdminBootstrap
SystemRoleGrantCreated, SystemRoleGrantDisabled
LastSystemAdminProtectionTriggered

Users and groups

Action
LocalUserCreated, LocalUserEnabled, LocalUserDisabled, LocalUserPasswordReset
UserTicketEmailContactUpdated, UserLandingPreferenceUpdated
LocalGroupCreated, LocalGroupEnabled, LocalGroupDisabled
UserAddedToGroup, UserRemovedFromGroup

Directory and LDAP

Action
DirectoryConfigCreated, DirectoryConfigUpdated, DirectoryConfigSecretUpdated, DirectoryConfigTested, DirectoryConfigDefaultsSuggested, DirectoryConfigSearchScopesBrowsed
LdapSyncRequested, LdapSyncSkipped, LdapSyncRunStarted, LdapSyncRunCompleted, LdapSyncRunFailed, LdapSyncGuardrailTriggered
LdapUserCreated, LdapUserUpdated, LdapUserEnabled, LdapUserDisabled
LdapGroupCreated, LdapGroupUpdated, LdapGroupEnabled, LdapGroupDisabled
LdapUserJitCreated, LdapUserJitUpdated

SAML

Action
SamlConfigCreated, SamlConfigUpdated, SamlConfigValidated
SamlLoginSucceeded, SamlLoginFailed
SamlUserJitCreated, SamlUserJitUpdated, SamlUserPreProvisioned
SamlGroupMappingCreated, SamlGroupMappingUpdated, SamlGroupMappingDeleted
SamlGroupMembershipApplied, SamlGroupMembershipRevoked

Customer Portal SSO

Action
CustomerPortalSsoConfigCreated, CustomerPortalSsoConfigUpdated, CustomerPortalSsoSecretChanged
CustomerPortalSsoHandoffSucceeded
CustomerPortalSsoUserJitCreated, CustomerPortalSsoUserJitUpdated
CustomerPortalSsoAccessGranted, CustomerPortalSsoAccessRevoked

There is no event for a failed handoff. Rejected handoff traffic is recorded as rate-limited operational telemetry, not as an audit row. Do not search for a failure event; there is none.

Two-factor authentication

Action
NonSamlTfaPolicyUpdated
NonSamlTfaEnrollmentStarted, NonSamlTfaEnrollmentCompleted, NonSamlTfaEnrollmentReset
NonSamlTfaChallengeSucceeded, NonSamlTfaChallengeFailed

Department access and automation

Action
DepartmentGroupAccessCreated, DepartmentGroupAccessUpdated, DepartmentGroupAccessEnabled, DepartmentGroupAccessDisabled
DepartmentAccessAutomationSettingsUpdated
DepartmentAccessAutomationRuleCreated, DepartmentAccessAutomationRuleUpdated, DepartmentAccessAutomationRuleEnabled, DepartmentAccessAutomationRuleDisabled
DepartmentAccessAutomationApplied, DepartmentAccessAutomationMappingApplied, DepartmentAccessAutomationReverted
ExternalParticipantAccessIdentityEnabled, ExternalParticipantAccessIdentityDisabled

Projects

Action
ProjectCreated, ProjectUpdated, ProjectActivated, ProjectDeactivated, ProjectViewed, ProjectStatusTransitioned
ProjectCustomFieldBindingCreated, ProjectCustomFieldBindingUpdated, ProjectCustomFieldValuesUpdated
ProjectRoleUpserted, ProjectRoleCleared
ProjectManagerAssignmentUpserted, ProjectManagerAssignmentCleared
ServiceProjectRoleMappingUpserted, ServiceProjectRoleMappingCleared
DepartmentProjectRoleFallbackUpserted, DepartmentProjectRoleFallbackCleared
ProjectTicketContextUpserted, WorkTicketProjectLinkUpserted, WorkTicketProjectLinkCleared
MetadataTagDefinitionCreated, MetadataTagDefinitionUpdated, MetadataTagAssigned, MetadataTagCleared

Saved work views

Action
AgentWorkViewCreated, AgentWorkViewUpdated, AgentWorkViewRemoved
ProjectRosterViewCreated, ProjectRosterViewUpdated, ProjectRosterViewRemoved

Tickets

Action
TicketCreated, TicketSafeFieldUpdated, TicketViewed
TicketReferenceAssigned, TicketReferenceBackfillCompleted
TicketProjectAssociationUpserted, TicketProjectAssociationCleared
TicketRelationshipCreated, TicketRelationshipCleared
TicketAttachmentUploaded, TicketAttachmentVisibilityUpdated, TicketAttachmentViewed, TicketAttachmentDeleted
PortalCartCheckoutRequested, PortalCheckoutCompleted, PortalBuyNowCompleted

The three Portal* names record a requester submitting selected tickets. They have nothing to do with payment.

Ownership and assignment

Action
TicketOwnerSet, TicketOwnerReassigned, TicketOwnerCleared, TicketOwnerBackfillCompleted
HeuristicAssignmentEvaluated
DepartmentManagerSourceUpserted, DepartmentManagerSourceCleared
DepartmentOnCallSourceUpserted, DepartmentOnCallSourceCleared

Redaction and reveal

Action
TicketContentRedacted
RedactionOriginalRevealRequested, RedactionOriginalRevealApproved, RedactionOriginalEvidenceRevealed, RedactionOriginalRevealAttemptDenied
RedactionRevealNotificationDeliveryAttempted, RedactionRevealNotificationDelivered, RedactionRevealNotificationDeliveryFailed, RedactionRevealNotificationSuppressed

Workflow

Action
TicketStatusTransitioned
WorkflowDefinitionCreated, WorkflowDefinitionUpdated, WorkflowDefinitionDeleted
WorkflowActionExecuted

Pause, Resume, NotifyWatchers, TicketUpdated, TicketResolved, and NoAction appear in workflow configuration screens. They are workflow action types and notification template names, not audit actions. Filtering on them returns nothing.

Collaboration

Action
TicketCommentCreated, TicketCommentUpdated, ExternalParticipantCommentCreated
TicketWatcherAdded, TicketWatcherRemoved
TicketParticipantAdded, TicketParticipantRemoved
TicketExternalParticipantAdded, TicketExternalParticipantRemoved, TicketExternalParticipantInvitationIssued, TicketExternalParticipantEnrollmentCompleted
ExternalParticipantTicketViewed, ExternalParticipantAttachmentUploaded, ExternalParticipantAttachmentViewed

Approvals and signatures

Action
TicketApprovalRequestCreated, TicketApprovalApproverAssigned, TicketApprovalViewed, TicketApprovalDecisionRecorded
TicketApprovalReminderQueued, TicketApprovalOutcomeNotificationQueued
TicketApprovalNotificationDeliveryAttempted, TicketApprovalNotificationDelivered, TicketApprovalNotificationDeliveryFailed, TicketApprovalNotificationSuppressed
RegulatedApprovalBlocked, RegulatedApprovalVerificationFailed, RegulatedApprovalSatisfied
RegulatedElectronicSignatureExecuted

Mail

Action
OutboundMailConfigCreated, OutboundMailConfigUpdated, OutboundMailConfigSecretUpdated, OutboundMailConfigSecretProtectedAtRest
OutboundMailConfigVerified, OutboundMailConfigVerificationFailed, OutboundMailConfigVerificationBlocked
OutboundTicketMailPreviewed, OutboundTicketMailDeliveryAttempted, OutboundTicketMailDelivered, OutboundTicketMailDeliveryFailed
TicketEmailUpdateConfigCreated, TicketEmailUpdateConfigUpdated
TicketEmailUpdateDeliveryAttempted, TicketEmailUpdateDelivered, TicketEmailUpdateDeliveryFailed, TicketEmailUpdateSuppressed
InboundTicketMailSecretUpdated, InboundTicketMailReceived, InboundTicketMailBound, InboundTicketMailClassified, InboundTicketMailBlocked, InboundTicketMailBindingFailed

Licensing

Action
ProductLicenseAgreementAcknowledged, ProductLicenseConfigured, ProductLicenseVerified
ProductLicenseActivated, ProductLicenseHeartbeat, ProductLicenseDeactivated, ProductLicenseCleared

Import

Action
ImportProfileDefinitionCreated, ImportProfileDefinitionUpdated, ImportProfileDefinitionEnabled, ImportProfileDefinitionDisabled
ImportDryRunExecuted
ImportApplyRunStarted, ImportApplyRunResumed, ImportApplyRunCompleted, ImportApplyRunFailed, ImportApplyRunReplayed
ImportApplyRunIdempotencyConflict, ImportApplyRunGuardrailRejected
ImportApplyRunReconciliationGenerated, ImportApplyRunReconciliationExported
ImportMaterializationRecorded, ImportUserCreated, ImportGroupCreated

Service-level agreement

Action
SLAPolicyCreated, SLAPolicyUpdated, SLAPolicyDeleted
SLAInstanceCreated, SLAInstancePaused, SLAInstanceResumed
SLAFirstResponseAchieved, SLAResolutionAchieved
SLAWarningEvent, SLABreachEvent

Business calendar administration is recorded. Four events are written by BusinessCalendarService:

Event When it is written
BusinessCalendarCreated A calendar is created
BusinessCalendarUpdated A calendar is edited, producing a new version
BusinessCalendarActivated A calendar is made selectable by policies
BusinessCalendarDeactivated A calendar is withdrawn from selection

SLA timing itself is per target and may run on 24/7 wall-clock time or a business calendar. See Limits and scope and Business calendars.

Catalogue, fields, departments, demo data

Action
ServiceCreated, ServiceUpdated, ServiceEnabled, ServiceDisabled
ServiceCatalogIconAssetUploaded, ServiceCatalogIconAssetRetired
ServiceCategoryCreated, ServiceCategoryUpdated, ServiceCategoryActivated, ServiceCategoryDeactivated, ServiceCategoryReordered
StatusDefinitionCreated, StatusDefinitionUpdated, StatusDefinitionActivated, StatusDefinitionDeactivated, StatusDefinitionReordered
CustomFieldDefinitionCreated, CustomFieldDefinitionUpdated, CustomFieldDefinitionDeleted, CustomFieldDefinitionReordered
SharedCustomFieldDefinitionCreated, SharedCustomFieldDefinitionUpdated, SharedCustomFieldDefinitionBound
DepartmentCreated, DepartmentUpdated, DepartmentEnabled, DepartmentDisabled
DemoDataSeeded, DemoDataPurged

Names that do not work as filters

Name Why it fails
OutboxEventProcessed, OutboxEventFailed Never recorded. No such events exist. Outbox handlers record domain events instead — SLABreachEvent, SLAWarningEvent, and the notification-delivery families. Outbox processing and retries go to the logs, not the audit history.
EvaluationLicenseAcknowledged Not an action. It is a field inside a SystemAdminBootstrap record. Filter on SystemAdminBootstrap instead.
SLABreachDetected Old name. Use SLABreachEvent.
LdapConfigUpdated Old name. Use DirectoryConfigUpdated.
LdapSyncStarted, LdapSyncCompleted Old names. Use LdapSyncRunStarted, LdapSyncRunCompleted.
DepartmentGroupAccessRemoved Old name. Use DepartmentGroupAccessDisabled or DepartmentGroupAccessUpdated, depending on what happened.

The old names never appear in stored records. Typing one returns zero rows — which is not evidence that nothing happened.

Ticket History shows only these 36

Ticket History on a ticket is a fixed subset of the audit record, not a filtered view of it. It shows exactly:

TicketCreated, TicketSafeFieldUpdated, TicketStatusTransitioned, TicketCommentCreated, TicketCommentUpdated, ExternalParticipantCommentCreated, TicketAttachmentUploaded, TicketAttachmentVisibilityUpdated, TicketAttachmentViewed, TicketAttachmentDeleted, ExternalParticipantAttachmentUploaded, ExternalParticipantAttachmentViewed, TicketContentRedacted, TicketWatcherAdded, TicketWatcherRemoved, TicketParticipantAdded, TicketParticipantRemoved, TicketRelationshipCreated, TicketRelationshipCleared, TicketOwnerSet, TicketOwnerReassigned, TicketOwnerCleared, TicketProjectAssociationUpserted, TicketProjectAssociationCleared, TicketExternalParticipantAdded, TicketExternalParticipantRemoved, TicketExternalParticipantInvitationIssued, TicketExternalParticipantEnrollmentCompleted, TicketApprovalDecisionRecorded, SLAInstanceCreated, SLAWarningEvent, SLABreachEvent, SLAInstancePaused, SLAInstanceResumed, SLAFirstResponseAchieved, SLAResolutionAchieved.

TicketViewed is recorded but deliberately excluded from Ticket History. TicketReferenceAssigned, TicketApprovalRequestCreated, TicketApprovalViewed, WorkflowActionExecuted, the approval notification events, and the ticket email events are also excluded. Use Audit Administration for those. ProjectViewed is excluded from project history in the same way.

What this list does not tell you

  • It does not prove every change in the product records an event. There is no single registry of action names in the product; they are written individually at each place that records one.
  • Event payloads vary. Some are metadata only, some are redacted, some are withheld.
  • Absence of an event in one search does not prove the action never happened. Widen the window and check the spelling first.

See Limits and scope for what append-only does and does not mean.