Obviously if they are logging all actions of all users, and there's some decent retention period, they can find out how many people got unintended access and what all they did with it. Recently, I got an advice from a C-level executive to include such analytics in ASPSecurityKit [0], because that's what companies are looking for these days. This GH incident makes me consider his suggestion more seriously.
This points to the last A in AAA of security which stands for Authentication, Authorization & Accounting, AAA moniker is commonly used in reference to either RADIUS or Diameter (network protocols), the concept is widely used for software application security as well.
So Accounting implies What resources were accessed, at what time, by whom, and what commands were issued?
0: https://ASPSecurityKit.net