A decision record
Security event handling checks device identity, sequence and outcome relationships. A recorded allow or deny is evidence of a decision, not proof of command completion.
Content and metadata
The adapter includes metadata redaction. Do not assume that every Specify workflow keeps file contents on your machine: submitted records, source material and processing jobs have their own data paths.
Private records
A record identifier or organization membership does not grant access to private content. Source and audience authorization still apply when material is reused.
Memory and Briefings
Work imports and Security sources preserve their own provenance and access requirements. A copied event does not automatically become a briefing source that every recipient can read.
Export availability
Do not rely on automated audit export or SIEM delivery from this page. Those require a supported, enabled integration.