Reporting, Analytics, and Audit
Nevis ID gives operators real-time dashboards and historical reporting: Identity Analytics tracks active users, authentication success rates, and registration growth, and Threat Intelligence surfaces risk events, high-risk users, and geographic attack patterns. Every administrative change is recorded in a history-enabled data model with actor and timestamp, and append-only audit logs retain critical events for 180 days, with log and event export to a SIEM or archival system for longer retention and custom reporting. A User 360 view combines profile, credentials, devices, active sessions, and event history in the management console, and reporting queries export data for analysis in your own tools. Live service status is public, and identity events feed your SIEM or visibility platform through the export path.
Also known as
identity analytics, dashboards and reports, audit trails, SIEM integration, observability.
At a glance
| Capability | Details |
|---|---|
| Dashboards | Insights area of the management console with selectable time periods: Identity Analytics and Threat Intelligence |
| Identity statistics | Active users, authentication success rates, and registration growth over time |
| Audit trails | Append-only audit logs with critical events retained for 180 days; every administrative change recorded with actor and timestamp in a history-enabled data model |
| Security event logging | Authentication events, failed attempts, session history for users and administrators, risk event history |
| User 360 | Profile, credentials, devices, active sessions, and event history in one view in the management console |
| SIEM integration | Log and event export for SIEM ingestion or longer archival; see also Integration, APIs, and Provisioning |
| Custom reports and export | Reporting queries over the API; data export for analysis in your own tools |
| Threat analytics | Real-time risk events, high-risk users and models, risk heat map, and browser distribution in Threat Intelligence; see also Risk, Fraud, and Adaptive Access |
| Consent records | Consent objects with version and acceptance date, history usable for audits and DSAR; see also Consent and Privacy Management |
| Observability | Incident communication at status.nevis.net |
| Alerting | Suspicious-login notifications to users with one-click session termination; service incident communication on the status page |
Concepts
- Reporting APIs: how reporting queries are exposed and used
- System overview: the architecture of an instance, including where logs live
How-to Guides
- Insights: the dashboard area of the management console
- Identity Analytics: active users, authentication success rates, registration growth, and the workflows built on them
- Threat Intelligence: risk events, high-risk users, heat map, and investigation workflows
- Console overview
References
- Reporting and data APIs: Query data, Session management, Notification
- Audit and history patterns: nevisAuth Audit Channel, nevisIDM Prune History Job, nevisAdapt Event
- Data model: the history-enabled entities behind the audit story
- Service status: incident communication