Reporting & audit
Every bypass window is a Salesforce record with a required reason, tracked status history, and preserved timing - which means your audit story is standard Salesforce reporting, not a special export.
The governance report pack
ControlLayer ships custom report types and a set of prebuilt reports covering the questions governance reviews actually ask:
- What is bypassed right now? - active windows with scope, objects, and time remaining
- What is scheduled? - upcoming windows before they go live
- What happened last quarter? - closed windows with full timing and reasons
- Who is doing the bypassing? - activity grouped by creator and scope
- What went wrong? - windows that hit errors or retries
Because these are standard reports on packaged report types, you can clone, filter, schedule, and subscribe to them like any other Salesforce report - e.g., a weekly digest of bypass activity to your governance channel.
Record-level audit detail
| Layer | What it answers |
|---|---|
| Window record | The declared intent: category, objects, scope, timing, and the required reason - preserved through and after the window's life |
| Status field history | Transition-level trail: every status change, timestamped and attributed |
| Record page history panel | The lifecycle narrative with actors - who created, what activated, when it expired |
| Coverage panel | The exact object set the window covered, with enforcement verification |
Answering the classic audit question
"Were any controls suppressed during the period, and if so under what authority?"
- Run the closed-windows report filtered to the period.
- Each row carries scope, objects, exact start/end, creator, and reason - the complete authority trail.
- For any window needing scrutiny, the record's field history provides the transition-level detail.
Windows are never deleted or reused, so history is complete by construction.