Review → Policy Logs
Policy Logs are the audit trail for Session Policy and File Transfer Policy. Use the selector above the table to switch between their decisions. Every decision made by a rule that has Log enabled is recorded here so you can answer what the policy allowed or denied, and why.
Only decisions from rules with logging turned on appear. If a category of activity is missing, enable Log on the relevant rule.
For Fact Policy compliance changes, see the Compliance heatmap and the resource’s or location’s History timeline.
What you can do
- Review the accept/deny decisions the policy made.
- See which rule fired, for which user and resource, and against which command or file paths.
- Jump from a log entry to the resource or retained session when that live target still exists. Deleted targets remain visible as immutable audit text and carry a Deleted badge; they are never linked to a different or missing object.
Session decision filters
All filters are optional and stack.
| Filter | Notes |
|---|---|
| Resource Type | Limit to one resource type. |
| Tags | Resources carrying any selected tag (shown when you can read tags). |
| User | Match a specific operator. |
| Action | Accept or Deny. |
| Decision Point | Connection (session open) or Command (a typed command). |
| From / To Date | Limit by decision time. |
| Search | Free-text match across the table. |
Session decision columns
| Column | Notes |
|---|---|
| Time | When the decision was made. |
| Action | Accept or Deny badge. |
| Point | Connection or Command. |
| Rule | The name of the rule that matched. |
| Resource | The resource involved. It links to the detail page while the resource exists; after deletion the recorded name remains with a Deleted badge. |
| User | The operator the session belonged to. |
| Command | The command that was evaluated (blank for connection decisions). |
| Session | For a command decision, opens the replay at that exact command sequence. Connection decisions open the matching session entry. After session retention removes the session, the recorded ID remains with a Deleted badge but is no longer a link. Recording retention may make replay content expire before the session row itself. |
Sort by Time, Action, or Point (other columns are not sortable); the default sort is newest first.
File transfer decisions
The File Transfer view can filter by direction, action, resource type, user, session, tags, date, and path text. Its table shows Time, Action, Direction, Rule, Resource, User, Source, Destination, and Session. Source and destination identify whether the path is on MisterShell or the Remote resource. The MisterShell side also shows its location as it existed when the policy decision was made. Resource and session links are available while those records exist; retained evidence is marked Deleted after either parent is removed.
Permissions
- Open the Policy Log:
app.policy.read. - See entries:
app.resources.readfor the resource’s current location, including the permitted location’s descendants. Moving a resource changes which entries you can see. - Entries for deleted, unattributed, or unlocated resources require unrestricted
app.resources.read. Policy-read alone shows an empty log.
Session links also require access to the retained session; opening recordings requires the corresponding recording access.