WS-3 · D-15 / D-16

Audit Log, RBAC & MFA

Tamper-evident activity ledger, role-based access control and multi-factor enrollment.

Activity ledger
TimestampActorRoleActionTargetIPResult
2026-06-05 14:48marta.k@festicket.ioOwnerfestival.publishTomorrowland 202682.45.110.4success
2026-06-05 14:31leo.k@festicket.ioFinancepayout.approvePO-2026-0184 · €184,20082.45.110.9success
2026-06-05 14:18systemauth.mfa.enforceall admin userspolicy-update
2026-06-05 13:55amy.t@festicket.ioSupportbooking.refundBK-9081 · €24082.45.110.21success
2026-06-05 13:40sven.o@festicket.ioMarketingcampaign.sendSummer Newsletter (412k)82.45.110.14success
2026-06-05 13:22rosa.l@festicket.ioOpsticket.tier.createGlastonbury · Day Pass82.45.110.55success
2026-06-05 12:51unknownauth.loginmarta.k@festicket.io203.0.113.11blocked-mfa
MFA enrollment
Authenticator app (TOTP)38/43 · 88%
Hardware key (FIDO2)12/43 · 28%
SMS (fallback only)41/43 · 95%
API keys & webhooks
  • sk_live_…a91frotated 14d ago
  • whsec_…7e22Stripe webhook
  • whsec_…b401Brevo webhook
Roles & permissions
Owner
2 members
*
Finance
3 members
payouts.*reports.readbookings.refund
Ops
11 members
festivals.*tickets.*checkin.*
Marketing
5 members
marketing.*customers.read
Support
8 members
bookings.*customers.*tickets.read
Read-only
14 members
*.read