Reference table
Audit event catalogue
Lists the audit event types Pensieve emits, what triggers each one, and the identifiers and context that accompany the entry.
This catalogue lists the audit event types Pensieve emits, what triggers each one, and the identifiers and context each entry carries. It reads alongside the audit trail, which sets out the fields and retention behind every entry.
Common context
Every entry carries a common set of identifiers, whatever the event. An event's own row below adds the context particular to it.
The person, the on-site bridge agent, or the internal job that acted.
The public patient reference, present when the event concerns a record.
The site the event ran at.
The stated purpose of the access.
Permitted, refused, held for context, or emergency.
The moment the event ran.
Access and change events
These events record a read of, or a change to, a patient record.
| Event | Trigger | Carries |
|---|---|---|
| Record view permitted | A staff member reads a patient record and the decision permits it | The actor, the patient reference, the site, the purpose, the time |
| Access refused | A decision refuses a read or an action | The actor, the patient reference, the reason class, the site, the time |
| Decision held for context | A decision permits once a named condition is supplied | The actor, the resource, the named condition, the time |
| Record change written | A staff member writes a diagnosis, note, order or result | The actor, the patient reference, what changed, the site, the time |
| Emergency access invoked | A treating clinician takes the emergency path over a partition or a marking | The clinician, the patient reference, the stated reason, the site, the window, the time |
Consent and directive events
These events record a change a patient makes to their own directives.
| Event | Trigger | Carries |
|---|---|---|
| Consent granted | A patient or a valid proxy grants a site access to the record | The patient reference, the site, the grantor, the time |
| Consent withdrawn | A patient withdraws a site's access to the record | The patient reference, the site, the time |
| Data partitioned | A patient hides data authored at one site from readers at another | The patient reference, the source site, the time |
| Access delegated | A proxy or a time-limited share is created | The patient reference, the grantor, the delegate, the expiry, the time |
| Sensitive grant witnessed | A grant covering a sensitive category records its witness | The patient reference, the granter, the witness, the category, the time |
Administration events
These events record a change an administrator makes to roles, rules or connections.
| Event | Trigger | Carries |
|---|---|---|
| Role or permission changed | An administrator changes a role, a posting or a permission rule | The administrator, the role or rule, the site, the time |
| Rule model changed | An administrator applies a change to the access rules themselves | The administrator, the change, the time |
| Sign-in | A person signs in at a workstation | The person, the site, the workstation, the time |
| Structural read | A read of non-clinical structure, sampled | The actor, the resource, the time |
Coverage differs by event
Record reads, refusals, held decisions, emergency access and consent changes are recorded in full. A read of structure that stays clear of a record is sampled, since it carries structure rather than clinical data.
Read how to produce an access history for one record in answering who saw this record.