Audit authority (*AUDIT) puts a user in control of the system auditing functions, allowing a user to read sensitive security logs that could expose system weaknesses. Users with *AUDIT can also manipulate the system values that control auditing, including user and object auditing. In addition, these users could turn off auditing for sensitive objects in an effort to obscure certain actions.