> For the complete documentation index, see [llms.txt](https://docs.powermonitor.com.br/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.powermonitor.com.br/en/power-monitor/auditoria.md).

# Audit

Overview of the Audit module: Power BI/Fabric events, report views, permissions and their history, behavioral risk, events of the application itself, sent emails, and capacity actions.

The **Audit** module is where you answer **"who did what, when, where, and with what result"**, both in your Power BI/Fabric environment and inside Power Monitor itself. While Governance shows the current state of artifacts and Monitoring tracks health and consumption, Audit keeps the **historical trail** for incident investigation, compliance (LGPD, ISO 27001, SOC 2), and access reviews.

**How to access:** **Audit** in the side menu. Reading most screens is open to all profiles; screens that expose sensitive personal data or infrastructure operations are exclusive to **Administrators** (see the table below). Event and permission data respect the user's **workspace scope**, and an administrator can hide specific pages for each user in [Users](/en/power-monitor/usuarios.md).

## The module's screens

| Screen                                                                           | What it records                                                                                                                                                                    | Who can access    |
| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------- |
| [Events Overview](/en/power-monitor/auditoria/geral-de-eventos.md)               | All Power BI/Fabric activity events (Activity Events): views, edits, deletions, sharing, refreshes, Copilot, administration                                                        | All profiles      |
| [Report Views](/en/power-monitor/auditoria/visualizacoes-de-relatorios.md)       | Only report and dashboard views, with the country, state, and city the access came from                                                                                            | All profiles      |
| [Permissions Audit](/en/power-monitor/auditoria/auditoria-de-permissoes.md)      | All permissions on workspaces, Fabric items, gateways, connections, and Power Embedded, with access inherited from groups and from the workspace                                   | All profiles      |
| [Permission history](/en/power-monitor/auditoria/historico-de-permissoes.md)     | Who gained, lost or changed access to workspaces and artifacts over time, and who had access on a past date                                                                        | All profiles      |
| [Behavioral risk](/en/power-monitor/auditoria/risco-comportamental.md)           | Daily, explainable score per person of changes in usage behavior. Feature with organization opt-in, already on in new installations                                                | **Administrator** |
| [Service Principals](/en/power-monitor/auditoria/service-principals.md)          | Applications (Service Principals) with direct permission in the environment, highlighting write access and workspace administration by third parties                               | All profiles      |
| [Row-Level Security](/en/power-monitor/auditoria/seguranca-em-nivel-de-linha.md) | RLS roles of each semantic model, members, DAX filters, and findings (labeled model without RLS, role without members or without filter)                                           | All profiles      |
| [Direct Sharing](/en/power-monitor/auditoria/compartilhamento-direto.md)         | People, groups, and applications with direct access to an item without having access to its workspace                                                                              | All profiles      |
| [E-mail Subscriptions](/en/power-monitor/auditoria/assinaturas-de-e-mail.md)     | Reports and dashboards with a scheduled email subscription, number of subscribers and of external-domain subscribers (without revealing who they are), delivery and change history | All profiles      |
| [Application Events](/en/power-monitor/auditoria/eventos-da-aplicacao.md)        | What users did inside Power Monitor: sign-ins, pages accessed, configuration changes, installation and consents, privacy operations                                                | All profiles      |
| [Email Audit](/en/power-monitor/auditoria/auditoria-de-emails.md)                | All emails sent by the platform to your organization                                                                                                                               | **Administrator** |
| [Capacity Actions](/en/power-monitor/auditoria/acoes-de-capacidade.md)           | Pausing, resuming, and changing the SKU of capacities, manually, by schedule, or by auto-scale                                                                                     | **Administrator** |

The [Service Principals](/en/power-monitor/auditoria/service-principals.md), [Row-Level Security](/en/power-monitor/auditoria/seguranca-em-nivel-de-linha.md), and [Direct Sharing](/en/power-monitor/auditoria/compartilhamento-direto.md) screens are access audits calculated from the same permissions collected in the scan that feed the [Permissions Audit](/en/power-monitor/auditoria/auditoria-de-permissoes.md).

{% hint style="info" %}
The aggregated **Report Access Dashboard** and **Permissions Dashboard** panels are in the **Dashboards** menu. See [Report Access Dashboard](/en/power-monitor/dashboards/dashboard-de-visualizacoes.md) and [Permissions Dashboard](/en/power-monitor/dashboards/dashboard-de-permissoes.md). **Scan Logs** are in [Mapping](/en/power-monitor/mapeamento/logs-de-scans-e-re-execucoes.md).
{% endhint %}

## Features by screen

Each page in the module has a **Features** section that presents, with a screenshot and step-by-step instructions, each feature of the screen. Summary:

| Screen                                                                           | Main features                                                                                                                                                                      |
| -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Events Overview](/en/power-monitor/auditoria/geral-de-eventos.md)               | Activity KPIs, **Critical Actions** shortcut, period, Category, Operation, and City filters, text and Status filters, event detail with JSON payload, export                       |
| [Report Views](/en/power-monitor/auditoria/visualizacoes-de-relatorios.md)       | View KPIs, period, Type filter (including via App and via Power Embedded), Country and City, detail with geolocation, **View insights**, export                                    |
| [Permissions Audit](/en/power-monitor/auditoria/auditoria-de-permissoes.md)      | **View/manage collection →** link (group cache), **Hide data**, Workspace, Object Type, Source, Object, and User filters, access source (direct, via group, via workspace), export |
| [Permission history](/en/power-monitor/auditoria/historico-de-permissoes.md)     | **Changes** tab (Granted, Revoked, Role changed, principal timeline) and **Who had access on** tab (lookup by date, with a coverage notice), export                                |
| [Behavioral risk](/en/power-monitor/auditoria/risco-comportamental.md)           | Organization opt-in and network signals, indicators and chart by severity, ranking with trend, history and factors per person, methodology, transparency (**Hide data** applies)   |
| [Service Principals](/en/power-monitor/auditoria/service-principals.md)          | Indicator cards, Power Monitor identity notice, list filters, grants modal with its own filters, export of the list and of the grants                                              |
| [Row-Level Security](/en/power-monitor/auditoria/seguranca-em-nivel-de-linha.md) | Coverage, roles, and label-without-RLS cards, RLS and Findings filters, detail with roles, members, and DAX filters, export                                                        |
| [Direct Sharing](/en/power-monitor/auditoria/compartilhamento-direto.md)         | Indicators, notices about groups without cache and partial read, search by object or person, Type, Workspace, Person, and Status filters, export                                   |
| [E-mail Subscriptions](/en/power-monitor/auditoria/assinaturas-de-e-mail.md)     | Artifacts with a subscription, External domain, and Need attention cards, Type and Last check filters, **Run history**, **Change history**, export, collection runs                |
| [Application Events](/en/power-monitor/auditoria/eventos-da-aplicacao.md)        | Period, filters with search for Category, Consent type, Event, Resource, Route, and User, Status filter, list of recorded events, export with IP and TraceId                       |
| [Email Audit](/en/power-monitor/auditoria/auditoria-de-emails.md)                | Sent, Failed, and Internal SMTP fallback cards, period, Status, Provider, Subject, and Recipient filters, email detail, export                                                     |
| [Capacity Actions](/en/power-monitor/auditoria/acoes-de-capacidade.md)           | Period, column filters, consumption status at the time of the action, action detail with the people responsible and emails sent, shareable link, export                            |

## Use cases

* **Security (CISO/SecOps):** identify external accounts with write permission, data sharing and exports, artifact deletions.
* **Incident investigation:** reconstruct the sequence of events around a report that disappeared or a model that was changed.
* **FinOps:** find out who paused, resumed, or changed the SKU of a capacity and what the consumption was at that moment.
* **Adoption:** measure who views which reports, from where, and through which path (portal, app, or Power Embedded).
* **Governance of the tool itself:** track who changed Power Monitor settings and check whether alert emails were delivered.

## Where the data comes from

| Source                                                       | Feeds                                                                         | Frequency                                                                                                                                                       |
| ------------------------------------------------------------ | ----------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Power BI/Fabric **Activity Events** (admin API)              | Events Overview, Report Views, Report Access Dashboard                        | Incremental collection at **01:23, 08:23, and 18:23** (Brasília time, UTC-3), while enabled in *Settings › Audit*                                               |
| **IP geolocation**                                           | Country, state, city, and provider of the events                              | New IPs are resolved every hour and kept in cache for 90 days                                                                                                   |
| **Power Embedded audit** (optional)                          | Real user behind accesses via Service Principal                               | Every 30 minutes, when the integration is configured in *Settings › Audit*                                                                                      |
| **Permission scans** + **Microsoft Graph**                   | Permissions Audit, Service Principals, Row-Level Security, and Direct Sharing | Inventory scans; group members updated once a day by the scheduled scan and, on demand, by the *Refresh groups* action in *Mapping › Inventory › Group Members* |
| **Activity Events** + **Power BI admin API** (subscriptions) | E-mail Subscriptions                                                          | Daily check at **10:00** (Brasília time, UTC-3) of the artifacts with a subscription created or changed in the last 30 days                                     |
| **Power Monitor itself**                                     | Application Events, Email Audit, Capacity Actions                             | In real time, at the moment of each action                                                                                                                      |

## Common features

* **CSV and JSON export** on list screens (**Export** button). The export respects the applied filters, is generated as a continuous stream by the server (without freezing the browser), and is limited to **50,000 rows** per file. The CSV opens correctly in Excel and is protected against formula injection.
* **List filters with server-side search** (multi-select) for users, objects, workspaces, events, and routes, you choose real values, without depending on typing the exact text.
* **Filters in the URL** in Email Audit and Capacity Actions: copy the address to share the same filtered view.
* **Hide data:** on the screens that show people (for example, Permissions Audit, Permission history, Direct Sharing, Behavioral risk and the [Report Access Dashboard](/en/power-monitor/dashboards/dashboard-de-visualizacoes.md)), the **Hide data** button masks names and e-mails on screen and in exported files. It is a screen-sharing convenience, not an access control; the choice is saved in the browser and applies to every screen that has the button.
* **Items per page:** paginated tables have a selector to choose how many rows appear per page.
* **Dates in your time zone**: date filters consider the full day in your browser's time zone.

{% hint style="warning" %}
Audit screens contain personal data (emails, IPs, location). When exporting or sharing screenshots, handle the content with the same care you would give customer data.
{% endhint %}

## How to use

### How to open an Audit screen

1. In the side menu, click **Audit**.
2. Choose the screen: **Events Overview**, **Report Views**, **Permissions Audit**, **Permission history**, **Behavioral risk**, **Service Principals**, **Row-Level Security**, **Direct Sharing**, **E-mail Subscriptions**, **Application Events**, **Email Audit**, or **Capacity Actions**.
3. **Behavioral risk**, **Email Audit** and **Capacity Actions** only open for **Administrators**; for other profiles, they lead to the **Not allowed** screen (Behavioral risk does not even appear in their menu).

### How to choose the right screen for your question

| Question                                                                                        | Screen                                                                           |
| ----------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| Who deleted, exported, or shared something in Power BI/Fabric?                                  | [Events Overview](/en/power-monitor/auditoria/geral-de-eventos.md)               |
| Who opened this report, when, and from where?                                                   | [Report Views](/en/power-monitor/auditoria/visualizacoes-de-relatorios.md)       |
| Who has access to this item, and through which path?                                            | [Permissions Audit](/en/power-monitor/auditoria/auditoria-de-permissoes.md)      |
| Which third-party applications can change or administer the environment?                        | [Service Principals](/en/power-monitor/auditoria/service-principals.md)          |
| Which semantic models have RLS, who is in each role, and which confidential models have no RLS? | [Row-Level Security](/en/power-monitor/auditoria/seguranca-em-nivel-de-linha.md) |
| Who sees an item without having access to its workspace?                                        | [Direct Sharing](/en/power-monitor/auditoria/compartilhamento-direto.md)         |
| Which reports are sent by email, including outside the organization?                            | [E-mail Subscriptions](/en/power-monitor/auditoria/assinaturas-de-e-mail.md)     |
| Who gained or lost access to a workspace, and who had access on a given date?                   | [Permission history](/en/power-monitor/auditoria/historico-de-permissoes.md)     |
| Did anyone change usage behavior in a way that deserves a conversation?                         | [Behavioral risk](/en/power-monitor/auditoria/risco-comportamental.md)           |
| Who changed a Power Monitor setting, or gave a consent?                                         | [Application Events](/en/power-monitor/auditoria/eventos-da-aplicacao.md)        |
| Was the alert sent? To whom?                                                                    | [Email Audit](/en/power-monitor/auditoria/auditoria-de-emails.md)                |
| Who paused, resumed, or changed the size (SKU) of a capacity?                                   | [Capacity Actions](/en/power-monitor/auditoria/acoes-de-capacidade.md)           |

### How to export a screen's data

{% stepper %}
{% step %}

### Apply the filters

Set up on the screen exactly the slice you want to take with you (period, user, object, etc.).
{% endstep %}

{% step %}

### Click Export

Click **Export** and choose **CSV** or **JSON**. The button shows a loading indicator while the file is generated.
{% endstep %}

{% step %}

### Save the file

The download starts automatically, with up to 50,000 rows. If something goes wrong, the message *Failed to export data.* appears. On the Events Overview and Report Views screens, the Country and City filters do not apply to the export.
{% endstep %}
{% endstepper %}

### How to share a filtered view

In **Email Audit** and **Capacity Actions**, the filters and the page are kept in the browser address:

1. Apply the filters.
2. Copy the browser address.
3. Send it to another administrator; when they open the link, they will see the same view.

On the other screens the filters are not kept in the address: agree with your colleague on which filters to apply, or share the exported file.

### How to investigate an incident using several screens

{% stepper %}
{% step %}

### Start with the event

In **Events Overview**, filter the period and the affected artifact and identify the suspicious operation (for example, a deletion or a change to a scheduled refresh) and the user.
{% endstep %}

{% step %}

### Check the access

In **Permissions Audit**, filter the user to understand through which path they had permission on the item (direct, through a group, or through the workspace).
{% endstep %}

{% step %}

### Check changes on the platform itself

In **Application Events**, see whether anyone changed monitoring or notifications in the same period.
{% endstep %}

{% step %}

### Confirm the notices

In **Email Audit** (administrators), check whether the incident alerts were sent and to whom.
{% endstep %}
{% endstepper %}

## Frequently asked questions

<details>

<summary>Why don't this afternoon's events appear yet?</summary>

Activity Events are collected three times a day (01:23, 08:23, and 18:23, Brasília time, UTC-3). An event that occurred at 2 p.m. appears starting with the 18:23 collection. Administrators can trigger a manual collection in *Mapping › Audit*.

</details>

<details>

<summary>New users of a group do not appear in the Permissions Audit.</summary>

In the Permissions Audit, click **View/manage collection →** and, on [Group Members](/en/power-monitor/mapeamento/membros-de-grupos.md), click **Refresh groups** to fetch the group members from Microsoft Entra ID again. Power Monitor also does this refresh on its own, once a day; after a scheduled run, the status of the last refresh shows **Automatic (scheduled)** in place of the user.

</details>

<details>

<summary>When I open "Email Audit" or "Capacity Actions", "Not allowed" appears.</summary>

These two screens are exclusive to administrators. The items appear in the menu for all profiles, but only administrators can open them.

</details>

<details>

<summary>An Audit screen disappeared from my menu.</summary>

An administrator may have blocked the page for your user in [Users](/en/power-monitor/usuarios.md). In that case, it no longer appears in the menu and direct access through the address leads to the **Not allowed** screen. Ask an administrator to unblock it.

</details>

## Related pages

* [Dashboards › Report Access Dashboard](/en/power-monitor/dashboards/dashboard-de-visualizacoes.md)
* [Dashboards › Permissions Dashboard](/en/power-monitor/dashboards/dashboard-de-permissoes.md)
* [Mapping › Scan Logs](/en/power-monitor/mapeamento/logs-de-scans-e-re-execucoes.md)
* [Settings › Audit](/en/power-monitor/configuracoes/auditoria.md)
* [Governance › Compliance › Labels and Certification](/en/power-monitor/governanca/conformidade/rotulos-e-certificacao.md)
* [Governance › Compliance › Departed Owners](/en/power-monitor/governanca/conformidade/responsaveis-desligados.md)
* [Governance › Compliance › Access reviews](/en/power-monitor/governanca/conformidade/revisoes-de-acesso.md)
* [Privacy and compliance](/en/power-monitor/governanca/conformidade/privacidade-e-conformidade.md): overview of the privacy screens


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.powermonitor.com.br/en/power-monitor/auditoria.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
