A live preview shows the current state of a job run, while an archived failure record preserves the exact broken row and its context after the run ends. The preview supports troubleshooting; the archive supports governance, auditability, and repeatable remediation. Without the archive, evidence is still visible, but it is not durable enough to govern.
How the two records serve different operational jobs
A live preview is operationally immediate. It is the view you use while a run is still in motion, so its value is speed, situational awareness, and rapid troubleshooting. An archived failure record is evidentiary. It captures the exact failed row, the surrounding context, and the broken state after execution ends, so the record can be revisited, explained, and acted on later.
The practical difference is durability. A preview can help you notice that something is wrong, but it is usually not the thing you would rely on for later governance or repeatable remediation. An archive turns a transient failure into a stable artifact that can support review, handoff, and consistent reprocessing.
Why preservation changes the meaning of the failure
The archived record does more than store a screenshot of the problem. It preserves the failure at the moment it matters, including the row or entity that broke, the context needed to reproduce the issue, and enough history to distinguish a one-off data defect from a recurring pipeline weakness. That makes it suitable for audit trails, operational follow-up, and controlled remediation.
Live preview data is inherently closer to a diagnostic lens than to a record of truth. Once the job finishes, the preview can change, vanish, or be overwritten by a later run. If your process depends on proving what failed, when it failed, and what the input looked like at the time, the archive becomes the authoritative object rather than the preview.
What changes in troubleshooting, governance, and remediation
For troubleshooting, the preview is about fast narrowing. It helps operators identify whether a failure is happening now, whether it is tied to the current input set, and whether the issue looks transient or systematic. For governance, the archive matters because it supports traceability, review, and repeatable remediation across teams and time.
The best way to think about the split is this: the preview answers “what is happening right now?” while the archive answers “what exactly failed, and can we prove it later?” When the same defect must be investigated, escalated, or corrected by someone who was not present during the run, the archived record is the one that preserves operational continuity.
Risk and Threat Considerations
When failure evidence is only visible in a live preview, the main risk is loss of durable proof. That creates gaps in auditability, slows root-cause analysis, and can make remediation inconsistent across repeated incidents or handoffs.
Failure mechanism: The preview is transient, so the broken row, its context, or the exact failure state may disappear or mutate after the run ends, leaving teams with incomplete evidence.
Impact: Without a persistent failure record, teams may struggle to demonstrate what happened, reproduce the issue, or prove that the fix addressed the same broken condition rather than a later variation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RR-01 — Roles, Responsibilities, and Authorities | Archived failure records support clear operational ownership and follow-up. |
| GV.OV-01 — Oversight of Risk Management Strategy | Durable failure records support oversight and repeatable remediation decisions. | |
| Recommendation — Assign clear ownership for preserving and reviewing failure evidence. Use archived failure evidence to inform oversight and corrective action. | ||
| NIST SP 800-53 Rev 5 | AU-11 — Audit Record Retention | An archived failure record is a retained operational record used for later review. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Archived records enable later analysis of the exact failed row and context. | |
| Recommendation — Retain failure records long enough to support audit and reconstruction. Review preserved failure records to drive consistent remediation. | ||
| ISO/IEC 27001:2022 | A.8.15 — Logging | Failure archives function as durable logs of what broke and when. |
| Recommendation — Preserve failure evidence so it remains available after the run ends. | ||
Practitioner Guidance
What to verify: Confirm that the archived failure record captures the minimum forensic context needed to replay or explain the issue, not just the error message. The useful record is the one that still makes sense after the job output has moved on.
Decision rule: Use live preview for active investigation, but require an archived record whenever the failure must support audit, handoff, or repeatable remediation. If the only evidence lives in the preview, treat it as operationally useful but not durable enough for governance.
Practitioner takeaway: The preview helps you see the problem; the archive lets you govern it. If a failure may need to be proved, reviewed, or fixed again later, persistence matters more than immediacy.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org