Enforcement events are a log of actions taken against users or sessions according to your organization’s workflows—such as self-policing steps or escalations. They appear on the Enforcement events tab in Protect, separate from raw security detections.Documentation Index
Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
Use this file to discover all available pages before exploring further.
Overview
Enforcement rows document what was done, who it applied to, why it ran (trigger), and whether it completed successfully. Use this tab to audit policy outcomes and handoffs to people or teams. For the list of detected activities that may lead to enforcement, see Threat events. To narrow either tab by date, user, or outcome, see Filters.The Enforcement Table
Events are listed with time, subject user, action type, how the action was initiated, and current outcome.
| Column | Description |
|---|---|
| Time | When the enforcement action was recorded. |
| User | The user the action applies to. |
| Action | The enforcement type that ran (for example self-policing or an escalation). |
| Trigger | Whether the action was started manually, by automation, or by another defined trigger. |
| Status | Whether the action succeeded, failed, or is still in progress. |

