mgr.audit (logins, 2FA changes, partner intakes, customs entries, etc.) is dispatched to the rules engine. Each enabled rule that matches the trigger + conditions fires its actions. Use {{verb}}, {{resource}}, {{subjectId}}, {{actor}}, {{detail.action}}, etc. as placeholders in action bodies.