Filter the Executions Audit by a Specific User
June 28, 2026 · InfraScout Team
When the dashboard redesign split Executions into a personal view and an admin Audit and Compliance trail, the admin view gave security teams and auditors a single surface showing every execution across the tenant. What it could not do was narrow that trail to one person. You could filter by actor type — user, workflow, or system — but answering "show me everything this person caused" still meant scanning the whole list. This release adds a user picker that does exactly that.
One person, the whole trail
Open Admin → Audit and Compliance → Executions and you will find a new user picker alongside the existing filters. Choose a person, and the list collapses to the executions that person is responsible for.
The important part is what "responsible for" means. The filter does not just match the executions a user ran directly. It matches every execution that ran on that user's behalf — both the AI and tool calls they made themselves and any workflow runs triggered for them behind the scenes. A scheduled workflow or an automated routine that acts in someone's name shows up under that person, not under an anonymous "workflow" bucket. That is the difference between a partial picture and a complete one when you are reconstructing what a single account set in motion.
This is built for the question auditors and security teams actually ask during a review or an incident: who caused this, and what else did they cause? Pick the person once, and the trail answers it.
A picker that keeps names readable
The picker shows each user by name so you can scan the list the way you think about your people. Names can be long, and an audit control crammed with overflowing text is hard to read, so the picker truncates long names neatly inside the control rather than letting them spill or wrap.
Because two people can share a display name, the picker keeps each person's email address close at hand — visible on hover and in the open menu — so you can tell colleagues apart before you commit to a selection. Choose someone, and the list filters immediately; there is no separate apply step.
TIP
Combine the user picker with the actor-type filter to sharpen a question further. Filter to one person and then to workflow activity to see only the automated runs that happened in their name — useful when you are verifying that a routine acted within its expected scope.
What's next
This release ships the user filter. Filtering the audit trail by date and time range is a planned follow-up, so you will be able to pair "who" with "when" in the same view. For now, the user picker gives you the "who" — the single most common starting point for an audit — and the rest of the existing filters narrow it from there.
Try it
Open Admin → Audit and Compliance → Executions, pick a user, and watch the trail collapse to everything that ran in their name. If you are new to the admin audit view, the dashboard redesign post explains how the personal and admin Executions surfaces fit together.
Questions or feedback? Reach us at info@infrascout.cloud.