Product Introduction
- Definition: Basedash Audit Logs is a native, API-accessible audit trail and security information and event management (SIEM) integration feature within the Basedash business intelligence (BI) and data analytics platform. It functions as a centralized, immutable log capturing all user and system interactions.
- Core Value Proposition: It exists to provide enterprise-grade data governance, security compliance, and operational accountability for analytics workflows. Its primary value is delivering a complete, attributable record of every action—from user sign-ins and data queries to AI agent activity and configuration changes—enabling security teams to prove compliance and answer critical access questions instantly.
Main Features
- Comprehensive Event Capture: The system automatically logs events across three core categories with detailed metadata (actor, action, resource, timestamp). How it works: Instrumentation within Basedash's application layer and query engine captures events in real-time. These are structured, enriched with user context from SSO, and written to a durable, secure log store. Technologies include event streaming and structured logging frameworks.
- AI Activity Attribution: This feature specifically logs and attributes all queries generated and executed by Basedash's AI assistant. How it works: When the AI generates SQL in response to a natural language prompt, the system creates a trace log linking the original user's question, the executed SQL query, the data source, and the requesting user identity. This ensures AI agent activity is held to the same audit standard as human users.
- Enterprise-Grade Log Management & Export: Provides tools for security teams to integrate the audit log into existing workflows. How it works: It offers configurable log retention periods to meet policy requirements, real-time streaming of JSON-formatted event data to external SIEM tools (like Splunk, Datadog) via webhooks, and full programmatic access through the Basedash Developer Platform API for custom reporting and backup.
Problems Solved
- Pain Point: The "analytics black box" problem, where sensitive company data is accessed and transformed in BI tools with no permanent, searchable record, creating blind spots for security, compliance, and incident response.
- Target Audience: Chief Information Security Officers (CISOs), IT and Compliance Managers, Data Governance Leads, and Security Analysts in organizations using or evaluating BI tools. Personas also include Data Engineers and Analysts who need to demonstrate responsible data usage.
- Use Cases: Responding to security audits (e.g., SOC 2, ISO 27001) with evidence of data access controls; conducting forensic investigations after a suspected data leak; monitoring and governing AI agent usage within analytics; enforcing internal data governance policies; and streamlining user access reviews during employee offboarding.
Unique Advantages
- Differentiation: Unlike generic BI tools that lack native auditing or offer only basic login history, Basedash Audit Logs provide deep, query-level visibility and AI attribution. Unlike bolting on third-party monitoring tools, it is a native, seamlessly integrated feature with granular context specific to analytics operations.
- Key Innovation: The native integration of AI query tracing into the standard audit log. This proactively addresses the emerging governance challenge of AI in data workflows, providing a technical model for accountable AI-assisted analytics where every AI-generated action is irrevocably tied to a human actor.
Frequently Asked Questions (FAQ)
- What specific events are logged in Basedash Audit Logs? Basedash Audit Logs capture three main event types: Access Events (user sign-ins via SSO, dashboard views, table opens, CSV exports), Query Events (every SQL query executed, whether by a user or the AI assistant), and Configuration Events (changes to team permissions, data source connections, and organization settings).
- How does Basedash handle audit log retention and compliance? Organizations on the Basedash Enterprise plan can configure log retention periods to align with their internal compliance policies (e.g., 90 days, 1 year, 7 years). Logs can also be streamed to your own SIEM for indefinite retention and further analysis within your security perimeter.
- Can I export audit log data for analysis in our security tools? Yes. Basedash Audit Logs support real-time streaming to external SIEM systems via webhooks and full data extraction via the Basedash API. This allows you to correlate Basedash events with other security logs in tools like Splunk, Sumo Logic, or Google Chronicle.
- How are queries made by the Basedash AI assistant audited? Every query generated by the Basedash AI is logged with a complete trace. The audit entry includes the natural language question asked by the user, the exact SQL query the AI constructed and executed, the timestamp, and the identity of the user who asked the question, ensuring full attribution.
- Do Basedash Audit Logs support role-based access control (RBAC) for viewing the logs? Yes, access to view and export the audit logs is itself a permission controlled by Basedash's RBAC system. Typically, only administrators and designated security personnel are granted access to the audit log interface and export functionalities.
