To set up user action auditing, use the Object Classes section on the navigation panel:

NOTE. When roles of the information security administrator and the application administrator are separated, the Object Classes section is available only for the information security administrator.
The security manager can automatically audit operations executed by system subjects and log information about executed operations to the access protocol. The logged operations are divided into general that can be executed with all object types, and specific ones that can be executed only with specific object types. Operation history is maintained for each object type: object changes, permission changes, object deletion. If full history is maintained, object changes by all operations are saved to history.
Change object access permissions
NOTE. Changing of permissions and disabling of auditing and history is available for several selected objects.
To apply the specified settings, click the Save button on the toolbar or side panel.
NOTE. If section parameters have been changed, an attempt to go to another section of the security manager or to close it displays a request to apply the changed settings.
Set attributes for object classes when the attribute-based access control method is used inn the following order:
For object classes. Attributes are set for all object types in the Attributes dialog box.
For a particular object type. Attributes are set for one object type on the Attributes tab while setting up access control.
For a particular object. Attribute value is set for one object if the corresponding object type contains attributes. One can only view specific object attributes on the Properties side panel in the security manager.
See also:
Setting Up System Security Policy | Object Classes | Selecting Auditing and History Operations | Creating Custom Attributes