Audit Log
Tamper-proof, searchable record of security-relevant actions in your organisation
The audit log is available on the Enterprise plan (sales-managed) only.
The audit log is a tamper-proof, searchable record of security-relevant actions in your organisation. It answers who did what, and when. Access requires the View audit log permission.
Narrow the log with filters
Use these filters to focus on the entries you care about.
| Filter | Description |
|---|---|
| Category | Filter by action category, for example Roles, Users, or Groups |
| Actor | Filter by the user who performed the action |
| Time period | Date range picker, defaulting to the last 30 days. Click Reset to restore that default. |
The search bar above the table matches free text against actor email and action name.
Read the log table
Each entry contains:
| Column | Description |
|---|---|
| Timestamp | Date and time the action was recorded |
| Actor | The user who performed the action |
| Category | The area of the platform affected, for example Roles, Users, or SCIM |
| Action | What was done, for example "Permission granted", "Permission revoked", or "User created" |
| Target | The object or user affected by the action, if applicable |
The table is paginated. Use the arrows to move between pages.
Export the log
Click Export CSV in the top-right corner to download the currently filtered log. The CSV suits compliance audits, incident investigations, and external reporting.
The audit log records administrative and security-relevant actions only. It never contains the content of user conversations.