Skip to main content
Every Privilege Elevation decision automatic, approved, denied, or blocked is recorded on the Events tab, giving you a complete, permanent audit trail independent of whether the rule that triggered it still exists.
Access to the Events tab requires the Privilege Elevation administrative permission. Without it, the tab isn’t shown, and its data isn’t reachable by direct URL either.

Open the Events tab

1

Open Privilege Elevation

In the left navigation, under Security, click Privilege Elevation.
2

Select the Events tab

Shows every recorded transaction, most recent first.
Privilege Elevation Events tab showing recorded transactions

The Privilege Elevation Events tab.

The Events grid

Events remain in the grid even after the rule that generated them is deleted — the audit trail doesn’t depend on the rule still existing.

What the Details column shows

Every event shows three consistent lines:
  • For Deny events, all three are fixed: Elevated as: None, Access Request: None, Privilege Elevation recording: disabled.
  • For a scheduled Auto-elevate rule blocked by its own schedule (outside allowed hours), the event logs as Deny with Elevated as: None, plus a note on why (for example, outside working hours).

Filters, search, and export

Default filters: When (date range, defaults to all time), Who (defaults to all users), Action (Auto-elevate / Require approval / Deny, defaults to all). More Criteria: Rule, Endpoint, Object, Processed By. Search matches User, Endpoint, Secret, Approver, and Object fields. Export produces a CSV containing every column, respecting whatever filters are currently applied.
Events tab filters including When, Who, and Action

Filtering the Events tab.

Session recording during elevation

If Session recording during elevation was enabled on the rule (available for Auto-elevate and Require approval, not Deny), Syteca can additionally record the elevated session itself — capturing screen, keyboard, and command input for the duration. What actually gets recorded depends on your license:
Deny mode never triggers or allows recording — there’s no elevated session to capture.

Overview

What Privilege Elevation does and how it’s licensed.

Creating and managing rules

Where Session recording during elevation is enabled per rule.

End-user experience

What triggers each of the Action values shown here.

Audit log

The administrative audit trail for Management Tool configuration changes.