Account

Audit log

A record of who changed access to your workspace, and when.

What it records

Changes to who can get in and what they can do. That is the deliberate scope: the log covers the decisions that are hard to reconstruct afterwards, rather than everything that happens in the product.

  • Someone invited, and whether that invite was accepted or revoked
  • Someone added directly, without an invite
  • Someone removed from the workspace
  • A member's role changed
  • A role created, edited or deleted
  • Workspace settings changed

It records what people in your workspace did. It is not a feed of what the platform observed, which is what history and alerts are for. A new blacklist listing is not an audit entry, because nobody on your team did it.

What an entry tells you

Who did it, what they did, who or what it was done to, when, and the IP address the request came from. Between them those answer the questions people actually bring to a log: was this us, and was it expected.

Finding a particular change

Search matches the person, the action and the thing acted on, so a colleague's email address is usually the fastest way in. You can also filter to one kind of action when you know what you are looking for and only need to know when it happened.

Where it earns its keep:

  • Somebody lost access they used to have. A role change is recorded, with who made it, which is quicker than comparing permissions from memory.
  • An unfamiliar name is on the team. The log says who invited them and when.
  • A review or a security questionnaire. Evidence that access changes are attributable rather than anonymous.

What it does not record

Reading things. Opening a report, viewing a placement result or looking at an asset leaves no entry, because a log of every page view would bury the changes that matter.

Day-to-day work inside the modules. Starting a placement test, editing a monitor rule or changing an alert channel is not an audit entry. Each of those screens shows its own current state and history, and that is where to look.

Anything outside your workspace. What happened to your mail in the world is placement tests and blacklists, not this.

People who have left

Entries stay after someone is removed, still attributed to them. A record you could edit by deleting a user would not be a record. See team and roles.

This is also the practical case against shared logins. The log attributes an action to an account, so a login two people use tells you an action happened but not who took it.