Three screens that have nothing to do with each other operationally and everything to do with each other in practice: they are how the organisation finds out what it did.
Audit Logs
Settings → Audit Logs, described as the cross-cutting audit trail. Every consequential action across the product, in one place.
This is the screen a compliance product is judged on, and it is worth knowing four things about it that are not obvious from looking.
Correlated events, and the trace timeline
An action is rarely one event. A dossier submitted fires a state change, an assignment, a notification and possibly an integration call — and reading them as four unrelated rows tells you almost nothing.
Two ways through it:
- Correlated events — everything sharing this event's correlation id. That is the business action.
- Trace timeline — everything sharing its trace id. That is the technical request.
When an event carries neither, the screen says so rather than opening an empty panel: this event has no correlation id, so there are no correlated events to open. And when only one row carries the identifier it says "Only this event carries this identifier — there is nothing else to show", which is a different fact from a search that failed.
The retention floor, and why it is stated
An audit trail is kept for a limited number of days, and the screen tells you the policy — N events are kept for M days.
More importantly: if you select a window that reaches further back than the trail exists, it says so: "The audit trail kept for this tenant begins on X. The window you selected reaches further back, so what you are seeing is not the whole story."
That sentence is the difference between an audit tool and a search box. A query returning nothing for last January could mean nothing happened, or that nothing is kept — and only one of those two answers should ever be given to an auditor.
Filtering has two halves, and the screen admits it
The server narrows by one event type and one severity at a time. Anything more specific is filtered in your browser, across the page you are looking at — and the notice says exactly that, along with how many of the events on this page matched.
So the count below a local filter is the unfiltered total, not the filtered one. Read the notice. A filtered view that silently reported a filtered count would be the most dangerous small lie this screen could tell.
Export stops, and says where
An export caps at a fixed number of rows: "Exported N of M audit events. The export stops at N rows — narrow the filters to export the rest."
A truncated export that did not say it was truncated is a spreadsheet somebody signs.
If you cannot open it
You do not have access to the Audit Centre — viewing the trail is its own permission and is deliberately not part of an ordinary administrator role. Chapter 14 is where that is granted.
Security
Settings → Security monitors identity activity: sign-in patterns, suspicious access, and security-sensitive audit events, filtered by date range, user or tenant. Four figures at the top — security events, high severity, unique users, latest event.
One thing to know before you go looking. The menu describes this entry as Password and sign-in, which is not what the page is. Changing your password is on the Account screen, not here. This one is a monitoring view. Verified on both screens; the menu description is the part that is out of step.
Notifications
Settings → Notifications is your own inbox — what the product wanted to tell you. A dossier assigned to you, an approval waiting, a processing failure.
The bell in the header shows unread ones; the screen shows all of them, and says You're all caught up when there is nothing.
It is a personal inbox, not an organisation-wide feed. It shows what concerns you. If somebody says "I never saw it", the question is usually whether they were on the case at all — chapter 13, dossier membership — rather than whether the notification was sent.
Support
Settings → Support files a request from inside the product: a description, and up to a small number of attachments — screenshots or documents that show the problem.
The prompt asks for the right thing: tell us what you expected and what happened instead. Two sentences in that shape are worth more than a paragraph of narrative.
There is one behaviour worth reading before you need it. If the message reaches us but does not get a ticket number, the screen says so and gives you a reference:
Your message reached us, but it did not get a ticket number, so a reply may take longer than usual. If it is urgent, write to support@dokgenius.com and quote the reference below.
Copy that reference. It is the screen telling you honestly that half of something failed, rather than showing a success and losing your request quietly — which is what most support forms do in that situation.
What you should have now
- Opened one audit event and followed its correlated events, so you have seen what an action really is.
- Read the retention line, and know how far back your trail actually goes.
- Understood that the count under a local filter is the unfiltered total.
- Your team told that the password change is on Account, not on Security.