Rule 6(1)(g)
Report templates
Each produces an immutable extract with the event chain preserved.
Every command executed by a specific identity across every monitored instance, with the classified columns each touched. The first thing asked for when an individual is under investigation.
Who accessed a specific sensitive table or column, over what period, and in what volume. The first thing asked for when a dataset is suspected of exposure.
All DBA and elevated-account activity, including break-glass usage and any attempt to alter auditing. Reviewed monthly regardless of whether anything was flagged.
Approved versus unapproved database changes — DDL, grants, role changes — reconciled against the change register.
Object access summary
The object-centric view, precomputed. Sorted by volume, because that is how a triage conversation actually starts.
Breach triage in practice
When an incident opens, the triage export is scoped to the incident window and the affected objects, and it carries the column classification alongside each event. That is what lets the impact assessment name affected Data Principals in hours rather than days — and the difference between those two timelines is the difference between meeting the 72-hour deadline and explaining why you did not.