Useful events

Team2FA records actions such as code issuance, invitations and administration without storing OTP values in audit records. Administrators can review organization activity and group admins can review activity for their groups.

A review routine

Look for unexpected access times, unused members, broad user group grants, repeated invitation failures and agent access that is no longer needed. Follow up with the owner of the external account when a pattern needs investigation.

Limits of the record

An audit entry confirms a code was issued through Team2FA. It does not prove a person logged in to the external service, and cannot see a code generated from a previously copied seed. Compare findings with the external service logs.