Audit log
Check the immutable records of creating, updating and deleting actions in the platform organization, including who acted and which resources changed.
Use it to investigate who changed people, roles, compliance records, and settings – and when those changes occurred.
Open Settings → Audit LogThe entries are immutable: the platform does not modify or delete them after they are written.
What each entry shows
Title: What each entry shows| Field | Meaning |
|---|---|
| Date | When the action is recorded |
| Actor | Who executed it – a user, an API key, or the system – plus the actor’s ID |
| Action | The operation, usually resource:verb (for example, create, update or delete) |
| Resource | Type and ID of the record that has been changed |
The actions cover organizational records, such as members, invitations, documents, risks, third parties, and authentication configuration.
Who can view and export
Section “Who can view and export”Owners and administrators can open the audit log in SettingsView recent records from your console, and then upload more as needed.
For a route dated outside of the console, export entries for a period of time. Exports are delivered as a CSV download link. You can also list and export through CLI, MCP, or n8n.
When to use it
Section titled “When to use it”- Confirms who invited, promoted, disabled or removed a person.
- Track changes to SSO, SCIM, or other organization settings.
- Provide evidence for an internal investigation or for an external audit.
Current limitations
Section entitled “Current limitations”- Retention is not configurable.
- There is no SIEM export or streaming integration yet, although the export format is compatible with the common SIEM intake pathways.
If you need configured retention or export SIEM, contact sales.