Distinguish “Content Access” and “Download” events
In the User Activity Report (and related activity logs), “Content Access” and “Download” events currently do not clearly distinguish between:
1) Actions explicitly initiated by an end user, and
2) Records generated by Box internal processing (e.g., system/background processing, thumbnail generation, programmatic/chunked access, or other non-user-facing operations).
As a result, admins cannot reliably interpret audit logs for security monitoring, compliance, and incident investigation. False positives or ambiguous records make it difficult to determine what a user actually did.
Request:
Please enhance the User Activity Report / activity log records for “Content Access” and “Download” so that user-initiated actions and Box-internal processing can be distinguished. For example:
- Subdivide event types (e.g., user download vs internal/system access), and/or
- Add identifiable fields/attributes (e.g., initiator/source type: user action vs internal process; reason/context such as thumbnail generation, chunked content access, automation/app, etc.)
Why this matters:
- Accurate audit and compliance reporting
- Reduced noise in security monitoring and investigations
- Clearer understanding of true user behavior vs system-generated activity
We would appreciate any approach that makes these records distinguishable and filterable in reporting/exports (and ideally also in the Events API, if applicable).