RivoShield records protection and security activity with UTC time, file or path when available, action, result, computer, Windows identity, application or process and reason. If metadata is unavailable, the product should leave it blank rather than invent it.
Events administrators should recognise
- DeleteBlocked: a delete request was denied.
- FolderArchived / FolderUnarchived: archive state changed through administration.
- ArchiveModificationBlocked: a prohibited mutation was denied in Archive mode.
- ProtectionLocationAdded / Removed: protected scope changed.
- AdminLoginSuccess / Failure: administrative authentication activity.
- ServiceStarted / DriverStarted: runtime lifecycle evidence.
Search and export
Administrators can search recent activity by filename, action, result, computer or user. CSV is useful for a readable report; JSONL retains complete machine-readable records. Store exports in an approved location.
Controlled clearing
Audit clearing should happen only after export and RivoShield administrator authentication. That sequence preserves evidence before records are removed from the active view.
A log line is not the whole test
A blocked audit event shows what the system recorded. Acceptance should additionally confirm that the target file physically remains and can still be opened. Evidence and outcome must agree.
