Activity records help your team trace service journeys and investigate reported problems. Depending on the feature and permissions in use, records can include page activity, completion, validation errors, integration actions, upload errors and review events.
Filter the audit view by submission, user, event type, result or date to narrow an investigation. Response Hub history adds response-specific evidence where the relevant history features apply. Library controls govern access to live data and audit views.
Use journey records to understand an error without changing the live service.
Limit access to audit information because it can contain service and user details.
Choose the relevant service, time period and event type when investigating.
Library administrators can require multi-factor authentication (MFA) for Builder users. An affected user must complete setup before accessing the library. The user-management view shows MFA setup status, helping administrators prepare for enforcement.
Platform administration also uses MFA. Service-user authentication is configured separately: the identity provider and service settings determine the sign-in experience and the applicable additional factors for respondents.
Prepare administrators and users before enabling a library-wide requirement.
Review invitations and accounts that no longer need access.
Plan account recovery and test access with the intended user roles.
Library permissions let you assign different responsibilities for administration, service design, QA deployment, Production deployment and live-data operations. A person can have different access in different libraries, so roles can follow the work they need to perform.
Use this separation to let designers build and test services while limiting who can publish changes or view submissions. Library-wide controls can further restrict Production deployment, live exports and analytics views.
Grant access for the person’s current responsibilities.
Separate design, release and live-data duties where your process requires it.
Review roles when someone joins, changes responsibilities or leaves.
Connect Builder and service journeys to supported identity providers, including Microsoft authentication and OpenID Connect. Organisation-controlled sign-in can give users a familiar access route and let your identity team apply its own sign-in policies.
Library authentication settings provide defaults for services, with separate QA and Production connections. Each service still chooses whether sign-in is required and which audience is permitted; configuring a provider alone does not restrict every service.
Choose identity arrangements that fit staff, external users or partner organisations.
Test sign-in, sign-out and account recovery in QA.
Review service access restrictions as well as provider configuration.
Manage library membership and access levels in one place. Named users, clear responsibilities and MFA setup visibility help administrators maintain access as teams and delivery partners change.
Account membership and library membership serve different purposes. Access to billing or account administration does not by itself define who can design a service, publish a release or work with live submissions in a library.
Assign an owner for library administration and access reviews.
Review temporary and partner access when the engagement changes.
Remove access that is no longer needed and check remaining administrators.
Connect services to your chosen systems using environment-specific credentials and permissions. API actions support configured headers and client certificates where required, while library integrations connect to file stores, data feeds and notification services.
These connections define where information is read, written or sent. Choose the minimum data and access required for each integration, and use QA to check both successful responses and failure handling before deploying live settings.
Give each connection a named owner and a defined purpose.
Keep test and Production credentials and destinations separate.
Use encrypted secret settings for reusable credentials.