Analytics Legends The knowledge platform for SAP Analytics
Academy module

Audit & Access Logs

Audit and access log evidence architecture: admin and data-access events pass through a DAC row-level gate into an immutable, retention-locked Audit Log Space reviewed by DPO, compliance and operations teams — architecture diagram for Audit & Access Logs, Analytics Legends Academy module M083

As of 2026-08-16

In a regulated-industry Datasphere deployment, the audit log is not optional. It is the contractual evidence of GDPR compliance (Art. 15 DSR response capability), SOX traceability, and EU AI Act data-access governance. A consultant who designs the audit log architecture and hands over a working review procedure is providing compliance insurance. This module teaches the configuration, the DAC audit, the regulatory mapping, and the operational handover — the four things a DPO and internal audit team will check on day one of a compliance review.

What you will learn

  • Configure the Datasphere Audit Log — enable tenant-level audit logging, designate the audit log Space, set the retention period, and verify that administrative and data-access events are captured correctly
  • Design a Data Access Control audit procedure: verify that DAC-restricted views prevent row-level access bypass, enumerate all privileged users, and produce a DAC configuration audit report
  • Map Datasphere audit log capabilities to GDPR Art. 15 DSR response requirements and EU AI Act Art. 71 data-traceability obligations — producing a compliance evidence register
  • Define and document a four-step operational audit log review procedure (weekly anomaly detection / monthly privilege review / quarterly retention verification / DSR-triggered extraction) that a client operations team can execute independently

Audit and access logs are not a post-go-live governance afterthought — they are the contractual evidence that a Datasphere or Business Data Cloud deployment complies with GDPR, SOX, and the EU AI Act's data-traceability requirements from day one. A senior consultant who designs the audit log architecture before the first user is provisioned is protecting the client from regulatory exposure. A consultant who leaves audit configuration for the operations team to sort out after go-live is leaving the client exposed to fines, audit findings, and reputational risk. The gap between those two postures is almost never technical difficulty — it is whether anyone put audit logging on the blueprint before the build started.

The Datasphere audit log model

Prerequisites

  • Intermediate hands-on experience on SAP analytics projects
  • Review core concepts first: C038, C041, C040

Outcomes

  • Configure Datasphere audit logging with correct retention and verify event capture for administrative and data-access events
  • Audit the DAC configuration to confirm row-level access restriction is enforced and cannot be bypassed
  • Map audit log capabilities to GDPR Art. 15 DSR and EU AI Act Art. 71 data-traceability obligations
  • Define and hand over an operational four-step audit log review procedure a client team can execute independently

Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.

Open in the app →