Monitor platform operations and audit activity
Use operational health and audit views to investigate platform-wide issues responsibly.
Updated 22 August 2026
Platform Admin tools expose platform-wide operational signals and privileged activity.
Use Operational health to review publishing, review-queue, moderation, and audit
signals that may require intervention. Refresh the view before acting on a stale item.
Use Audit log to search actions, actors, and targets. The screen loads the newest
bounded page first; select Load older events until the full investigation window is
present before searching or choosing Export loaded view. Export only when an
authorised investigation or retention process requires it. An audit event records that
an action occurred; it does not by itself establish why the action was taken.
Instructor, taxonomy, AI-rate, credit-adjustment, and Platform-team changes commit
their domain result and Platform audit event together. A failure cannot leave a saved
change without its audit history. If the response is interrupted, retry the unchanged
request from the same page; its retained request identifier confirms the earlier
result without applying it twice. A version-conflict message means another
administrator changed the record, so refresh and review the latest state before
starting a new request.
Start with the narrowest relevant record, confirm the affected account or content, and
keep remediation inside your assigned permissions. Do not change account access merely
to inspect another workspace. Record material decisions through the platform workflow
so later reviewers can reconstruct what happened.
The scheduled Platform operations check runs hourly. Operational health shows the
latest durable run, whether it completed fully, overdue moderation cases, and stuck or
failed notification delivery. Evidence cleanup separates stale uploads, upload
reconciliations, and evidence whose retention cleanup is overdue. Account lifecycle
work separates open, stale, and reconciliation-required account changes. Access
integrity counts stale or failed enforcement finalizations and active restrictions
whose live account or course state no longer matches the enforcement record. Public
image cleanup counts expired or interrupted cover/profile upload reservations and
records that require reconciliation. Stop further changes on reconciliation-required
records and escalate them to a Platform owner. A partial run is treated as unhealthy
so deferred or failed work cannot look successful.
Platform administrators can expand these totals under Actionable operational
records. Each queue is bounded and can load another page without replacing records
already shown:
Secure evidence upload cleanup links the private upload to its moderation case
and shows status, error, attempts, age, eligibility, lease, and private-object path.Secure evidence retention cleanup links expired private evidence to its case and
shows the retention deadline, retry state, worker lease, attempts, and exact private
object. Records appear only after the case, appeals, enforcements, and legal holds no
longer block deletion.Account lifecycle recovery links the affected account and any moderation case,
and shows the intended status change, version check, attempts, age, and last error.Public image cleanup links each cover or profile-photo reservation to the upload
owner and shows its exact public-object path, purpose, eligibility, lease, and retry
history.Enforcement and access integrity links the case and affected account when
available, and shows the ledger identifier, observed live state, age, and failure.
Health-only analysts and reviewers see redacted totals and escalation guidance, not
raw account emails, private-object paths, or case details. Platform administrators can
inspect the bounded records, but only the Platform owner can start recovery or record
an escalation. Ordinary cleanup remains a scheduled operation.
Owner actions always require a reason and the current record state. Retry cleanup
claims one exact evidence or public-image row, respects any active worker lease,
rechecks case, legal-hold, attachment, and ownership safety, and uses the existing
token-fenced finalizer after Storage responds. Retry account recovery claims one
lifecycle operation, verifies current Auth state, applies only its recorded target,
and uses the atomic account finalizer; access remains fail-closed if verification is
interrupted. Inspect state locks the enforcement and case and records its
classification without changing access. A stale pending enforcement offers Confirm
uncommitted and mark failed only when the server proves that neither its case event
nor audit finalization committed. Submit any replacement through the linked case.
Record escalation preserves the current record version and the owner’s reason in
the audit log, but deliberately does not acknowledge, hide, or resolve the red health
count. Do not delete Storage objects, edit lifecycle or enforcement rows, or replay
appeal tokens outside these workflows. Refresh after every action before proceeding.
The check alerts the case assignee, or active Platform Admins when a case is unassigned,
four hours before an active moderation SLA expires and again after it becomes overdue.
It sends pending moderation email notifications and retries eligible temporary failures
with bounded backoff. A permanent delivery error, unavailable retry content, or eight
failed attempts becomes a terminal dead letter shown under Unresolved email
deliveries. Only Platform administrators can inspect recipient details or resolve
this work. Select a case number to open the linked moderation case before acting. First
correct the underlying address, template, or email configuration, then:
Choose Requeue email for an ordinary notification that should be delivered. It
returns to the bounded retry queue immediately. For an account recipient, the retry
refreshes the destination from their current registered email. If no deliverable
address remains, update the account email or acknowledge the delivery instead.Choose Acknowledge and record a reason when no further delivery should occur. The
failure stays in the audit trail but leaves unresolved work.Choose Issue fresh appeal link and record a reason for a failed appeal email. The
failed bearer link is never replayed; the system creates a new private token and sends
a new email for the active enforcement. If that replacement cannot be delivered, its
failure appears as new unresolved work.
Appeal links are stricter because a failed or unconfirmed link is revoked. If a
delivery process stops before it can confirm the send, maintenance revokes that link
after 15 minutes and marks it for operator attention. The raw link cannot be recovered
from the delivery record.
The same maintenance run removes appeal-token records 90 days after the token was used,
revoked, or expired, and deletes private moderation evidence after its 90-day retention
date. Evidence is retained while its case,
enforcement, or appeal is active and while a legal hold applies. If scheduled execution
is unhealthy, treat overdue cases, delayed notifications, and expired evidence as an
operational incident rather than relying on manual reminders.
Public image maintenance separately removes exact-path objects left by expired or
failed course-cover/profile-photo upload reservations, retries bounded cleanup work,
and moves repeatedly failed work to reconciliation. It also removes old terminal
reservation history after its audit window. Use the Public image cleanup health
signal to detect a stopped scheduler; do not bypass the reservation or cleanup
workflow with direct public-bucket changes.
Did this page help you?
Your response helps us improve this guide.