A user contacted me this morning because he no longer had access to some functionality, to which I had given him access the same day. Turns out that the user has been removed from a/the group 'administrators'.
When checking the audit log, the user 'system' appears to have made the change. Off course, asking the person who might have made the change would be an option too - but I would like to know why it is logged as 'system' when a user performs the action?
Unless the 'system' user has decided to remove 3 users from a group by itself, or I might be missing something
?