What Kolleno records
When SIEM audit logging is active, Kolleno records security-relevant events across your account. These include:
Sign-in activity: successful and failed sign-ins, and suspected brute-force or rate-limit events.
User and access management: invitations sent and accepted, role changes, permissions granted or revoked, and access revocations.
Teams: members added or removed, and team permission changes.
Two-factor authentication: 2FA enabled or disabled.
Downloads: report and file downloads.
Email settings: email signature and inbox-account changes.
Payment configuration: bank accounts, payment settings, and payment-provider connections (such as Stripe, Adyen, Nuvei, GoCardless) added, updated, or removed; and saved payment methods removed.
Templates and workflows: template changes and workflow email-recipient changes.
AI guardrails: when an AI agent guardrail is triggered.
Files: files binned or deleted.
This list is not exhaustive. The events Kolleno records may change without notice as the Kolleno security team reviews and adjusts what is captured.
Each event carries useful context where available: who performed it, their email, source IP, user agent, what was affected, and whether it succeeded.
How long events are kept
Events are held for your account's retention period (between 1 and 180 days, set when the add-on is enabled) and are then automatically deleted. Because of this, your SIEM is the long-term record, so make sure it polls often enough that no events age out before they're collected. To change your retention period, contact your account manager.
