Skip to content

Reference table

Audit event catalogue

Lists the audit event types Pensieve emits, what triggers each one, and the identifiers and context that accompany the entry.

This catalogue lists the audit event types Pensieve emits, what triggers each one, and the identifiers and context each entry carries. It reads alongside the audit trail, which sets out the fields and retention behind every entry.

Common context

Every entry carries a common set of identifiers, whatever the event. An event's own row below adds the context particular to it.

actoridentity

The person, the on-site bridge agent, or the internal job that acted.

patientreference

The public patient reference, present when the event concerns a record.

sitestring

The site the event ran at.

purposestring

The stated purpose of the access.

outcomestring

Permitted, refused, held for context, or emergency.

attimestamp

The moment the event ran.

Access and change events

These events record a read of, or a change to, a patient record.

EventTriggerCarries
Record view permittedA staff member reads a patient record and the decision permits itThe actor, the patient reference, the site, the purpose, the time
Access refusedA decision refuses a read or an actionThe actor, the patient reference, the reason class, the site, the time
Decision held for contextA decision permits once a named condition is suppliedThe actor, the resource, the named condition, the time
Record change writtenA staff member writes a diagnosis, note, order or resultThe actor, the patient reference, what changed, the site, the time
Emergency access invokedA treating clinician takes the emergency path over a partition or a markingThe clinician, the patient reference, the stated reason, the site, the window, the time

These events record a change a patient makes to their own directives.

EventTriggerCarries
Consent grantedA patient or a valid proxy grants a site access to the recordThe patient reference, the site, the grantor, the time
Consent withdrawnA patient withdraws a site's access to the recordThe patient reference, the site, the time
Data partitionedA patient hides data authored at one site from readers at anotherThe patient reference, the source site, the time
Access delegatedA proxy or a time-limited share is createdThe patient reference, the grantor, the delegate, the expiry, the time
Sensitive grant witnessedA grant covering a sensitive category records its witnessThe patient reference, the granter, the witness, the category, the time

Administration events

These events record a change an administrator makes to roles, rules or connections.

EventTriggerCarries
Role or permission changedAn administrator changes a role, a posting or a permission ruleThe administrator, the role or rule, the site, the time
Rule model changedAn administrator applies a change to the access rules themselvesThe administrator, the change, the time
Sign-inA person signs in at a workstationThe person, the site, the workstation, the time
Structural readA read of non-clinical structure, sampledThe actor, the resource, the time

Coverage differs by event

Record reads, refusals, held decisions, emergency access and consent changes are recorded in full. A read of structure that stays clear of a record is sampled, since it carries structure rather than clinical data.

Read how to produce an access history for one record in answering who saw this record.