Skip to main content
Rekkeh keeps three separate security records, not one merged audit trail. Each answers a different question and is read in a different place. Use this page to identify which record you need.

The three records at a glance

Emergency response timeline

The Response timeline is the per-alert record of every action, who took it, and when. It includes: Raised, Acknowledged, En route, Dispatched, On scene, Resolved, Cancelled, Responder assigned, SLA breached, and Escalated to supervisors. The actor is shown by name when available, otherwise by role, and falls back to System for automatic events. Before any action is taken, the timeline shows: Nothing logged yet. Acknowledging or dispatching adds the first entry.
SLA breach and escalation events appear only in the emergency response timeline. They are not entries in the Facility Audit Log.

Incident audit tab

Each incident record has an audit tab listing all audit rows for that incident, newest first. Each entry shows the action, the actor role, a timestamp, and parsed metadata. Actions you may see include:
  • incident.created, incident.updated, incident.note_added
  • emergency.acknowledged, emergency.en_route, emergency.arrived, emergency.resolved, emergency.cancelled
  • emergency.duress_raised, emergency.manual_raised, emergency.note_added

Facility Audit Log

The Audit Log page records all audited admin activity across the facility. It lists up to 50 entries per page, newest first. Each entry shows the action, actor, entity type, a truncated entity ID, relative time, and expandable metadata. Use the filters to narrow the list:
  • Action filter — free text (e.g., incident.updated)
  • Entity type filter — All types, incident, invite, access_event, user, or visitor_watchlist
Only estate managers and super admins can open the Audit Log. Emergency audit rows are stored as incident entities, so use the incident entity-type filter to find emergency activity.

Which record to use

What’s next