Audit & Access Reviews
Cloudaware helps teams produce and maintain audit evidence by capturing access, configuration, and operational change data across the platform.
Use this guide to understand how Cloudaware supports audit readiness through audit trails, CMDB change history, module-specific logs, and exportable evidence for internal reviews and external audits.
Audit and access reviews prove two controls:
- You can answer who changed what, when (audit trail).
- You keep access least-privilege over time (review + remediation).
What To Audit (Minimum Scope)
Capture and retain change history for:
- RBAC: profiles, permission sets/groups, and custom permissions.
- SSO/MFA: IdP metadata/cert rotation, group claims/mapping, and session policy changes.
- Integrations: credential changes, scopes, and schedule changes.
- Policy configuration: policy/policy-pack changes and evaluation cadence changes.
For baseline guidance, see History & Audit.
Where Audit Trails Come From
Use a combination of:
- Setup Audit Trail (Salesforce UI) for RBAC and identity configuration changes.
- Change History (CMDB) on configuration items for operational investigations.
- Module-specific logs where applicable, then export to your SIEM if required.
See also: Change Management.
Access Review Cadence
Run a quarterly access review, or align reviews to your internal certification cadence:
- Profiles: confirm baseline profiles remain minimal; remove broad rights from non-admin profiles.
- Permission sets and groups: validate persona mapping; remove unused and legacy sets.
- Custom permissions: review sensitive feature toggles (for example, permissions that allow creating shared artifacts).
- Public scopes/views: confirm who can create shared CMDB list views and whether that is still appropriate.
- Break-glass access: verify at least one non-SSO admin exists and test access. See SSO & MFA.
Audit-Ready Evidence
Keep an evidence pack for each review cycle:
- Access review report: who has what access, what changed, and what was removed.
- Approvals and attestations: who reviewed the access and who signed off.
- Exported audit logs for the review window, or SIEM links.
- Exceptions and rationale, such as temporary elevated access or muting group variants.
Related: History & Audit and Change Events.
See also: