empowsec Audit Logs, Impersonation, and GDPR Deletion

Accountability in a security awareness platform works on two levels. The first is the obvious one: tracking whether employees completed their training, passed their quizzes, and engaged with phishing simulations. The second is less visible but equally important for organizations under compliance and data protection obligations: tracking what the platform itself did, who accessed it with what permissions, and whether actions affecting users were taken in accordance with documented procedures. Without this second layer, audit evidence is incomplete. empowsec addresses both levels through comprehensive audit logging, a fully logged impersonation capability for support workflows, and a structured GDPR account deletion process that closes the data lifecycle cleanly.
This article covers what empowsec logs, how impersonation works and why it is logged, and how the GDPR account deletion workflow operates - from initial request through approval and notification.
Comprehensive Audit Logging
empowsec keeps audit logs that cover a wide range of activity on the platform. API usage is logged, so any programmatic access to the platform - whether by the company's own integrations or by a reseller's tooling - creates a traceable record of what was requested and when. Assignment changes are logged, so there is a record when a training assignment is created, modified, or removed, and who initiated that change. User activity is logged, providing a history of meaningful actions within accounts.
Impersonation sessions receive their own logging entry, which is covered in more detail below. Together these log categories give administrators and auditors a continuous, timestamped record of what happened on the platform and who was responsible for it. This is the foundation of accountability: the ability to answer 'who did what, when, and through what means' with reference to a tamper-evident log rather than relying on memory or self-reporting.
For organizations under compliance frameworks such as ISO 27001, NIS2, or SOC 2, audit logging is not optional - it is a control requirement. ISO 27001 Annex A explicitly calls for logging of user activities, exceptions, and information security events. NIS2 imposes incident recording and documentation requirements. Having a platform that generates these logs automatically, without requiring custom integration or external log shipping, reduces the compliance burden and removes one more item from the manual controls checklist.
Impersonation: Support Without Shared Passwords
Impersonation is the capability that allows an admin or reseller to act as another user within the platform - navigating the interface as if they were that user, seeing what that user sees, and performing actions on their behalf. This is a common and legitimate support tool: when a user reports that something is not working correctly, the fastest way to diagnose and resolve the issue is often to see the platform from their perspective directly.
The risk with impersonation is that it can become an accountability gap: if support staff can silently become any user in the system, it becomes difficult to trace back actions taken during a session to their true actor. empowsec addresses this by logging every impersonation session. The log record captures who initiated the impersonation, which user was impersonated, the start and end time of the session, and any meaningful actions taken during it. This means the audit trail does not have a hole where impersonation occurred - the session is as traceable as any other action in the log.
For organizations that provide support access to external parties - whether to empowsec's own support team, to their MSP's technical staff, or to a reseller administrator - this logging provides reassurance that access was bounded and documented. An auditor reviewing the log can see exactly when support access was used, for how long, and to what end. This is substantially better than the alternative, which is shared credentials or untracked administrative access that leaves no meaningful evidence of what was done.
Resellers in particular benefit from impersonation capability because supporting multiple client companies at scale requires the ability to troubleshoot within any client's environment. With logged impersonation, the reseller can provide this support while maintaining a clean record that clients can review if they ever need to understand what their service provider did within their account. This transparency supports the trust relationship between reseller and client that is fundamental to a managed service model.
GDPR Account Deletion: Request, Approval, and Notification
The General Data Protection Regulation gives individuals the right to request deletion of their personal data - what GDPR calls the 'right to erasure'. For a security awareness platform that holds employee training records, phishing simulation results, risk scores, and certificate data, this right is a real operational concern. An employee who leaves an organization, or who exercises their rights as a data subject, may legitimately request that their empowsec account and associated data be deleted.
empowsec handles this through a structured account deletion workflow. When a user requests account deletion, the request enters an approval process rather than executing immediately. This approval step is important for several reasons. It prevents accidental or unauthorized deletions. It gives the organization the opportunity to verify that the request is legitimate and that there are no dependencies - for example, whether the user's certificates are required as compliance evidence, or whether there are active assignments that the organization needs to resolve before the deletion proceeds.
The deletion itself can be handled as immediate or deferred. Immediate deletion removes the account and its data promptly once approved. Deferred deletion schedules the removal for a later point, which may be appropriate when the organization needs a transition period - for example, to ensure training records are captured in an external report before they are permanently deleted. Both options are supported by the workflow.
Resolution Notifications and the Data Lifecycle
Once a deletion request is resolved - whether approved for immediate deletion, scheduled for deferred deletion, or declined - empowsec sends resolution notifications to the relevant parties. The user who made the request is notified of the outcome. The administrator who handled the approval receives confirmation. This notification trail completes the documented lifecycle of the deletion request: a record exists showing that the request was received, reviewed, decided, and communicated, which is precisely what GDPR data protection impact assessments and subject access request procedures require.
The combination of a structured request process, an approval workflow, options for immediate or deferred execution, and resolution notifications is not bureaucratic overhead - it is the minimum documented process that organizations need to demonstrate that they handle data subject rights responsibly. Without this workflow, responding to a GDPR deletion request would require manual coordination, creating an ad hoc process that may not produce consistent or auditable results. empowsec makes the process built-in and consistent, so every deletion request is handled the same way and leaves the same kind of evidence.
Accountability as a Security Practice
Audit logging, impersonation tracking, and GDPR deletion workflows are sometimes treated as compliance overhead rather than security practices. This framing misses their real value. Audit logs are security infrastructure: they are how organizations detect anomalous access, investigate incidents after the fact, and demonstrate to regulators that their systems operate under meaningful controls. A security awareness platform that does not log its own activity is asking organizations to take on trust what their security software is doing - which is not how security should work.
Logged impersonation is a specific form of this: it ensures that the privileged access that support workflows require does not create a category of untraceable action. Every session can be reviewed. Every action can be attributed. This is the standard we would expect from any security tool that holds sensitive training and assessment data about employees, and it is the standard empowsec maintains.
GDPR deletion workflows extend the same principle to the data lifecycle. Data protection law in the European Union and many other jurisdictions requires organizations to honor data subject rights in a documented, traceable way. empowsec building this workflow into the platform means that compliance with these obligations is operationalized rather than relying on email threads and manual tracking.
What This Means for Your Team
- Comprehensive audit logs cover API usage, impersonation sessions, assignment changes, and user activity - providing a continuous, timestamped record for incident investigation and compliance audits.
- Logged impersonation means every support session - whether by an admin, reseller, or empowsec support staff - is documented with actor, target, start time, and end time, removing accountability gaps.
- GDPR account deletion workflow routes requests through an approval process before execution, supporting responsible handling of data subject rights with documented, traceable outcomes.
- Immediate or deferred deletion options give administrators flexibility to handle deletions at the right time for the organization without ignoring or delaying the underlying right.
- Resolution notifications to both the requesting user and the approving administrator complete the documented lifecycle of every deletion request.


