A financial auditing app can show continuous ingestion while privileged paths never emit events. The dashboard stays green; the story stays wrong. Database compliance checks have to ask which actions are silent by design.
Inventory emitters before you trust volume
List administrative actions that bypass application logging: direct SQL, break-glass roles, vendor consoles. For each, note whether the database, host, or identity provider produces a substitute trail. Missing emitters become findings even when byte volume looks healthy.
Compare clocks and identities
Skewed timestamps and mismatched identity formats make joins look like gaps. Normalize clocks and map technical principals to human stewards before declaring a control ineffective. Many “missing” events are rename problems.
Practice the uncomfortable demo
In class we intentionally create a privileged change that never reaches the auditing app, then ask learners to spot it from adjacent signals. That discomfort is the point — quiet rooms learn faster than confident dashboards.