What the audit log records
The Audit Log is one unified feed that merges two kinds of events into a single table:- Changes — someone created, updated, or deleted a record.
- Admin Access — an org admin used the audited admin view to look at members’ personal resources (the implicit-access path described under Privacy).
The Actor column shows the person’s email, or system for automated changes.
Resource types
The Resource filter uses friendly names for the kind of record involved. Which options appear depends on the row kind:Filtering the log
Use the controls at the top of the log to narrow the entries shown. Filters combine, so you can scope to a specific event type, user, department, resource, action, and date range simultaneously.Navigating pages
Use the pagination controls at the bottom of the table to move through the full log.Permissions
The audit log is append-only. Entries can be filtered and read from this screen, but they can never be altered or deleted — by anyone, including org owners. This immutability is what makes the log credible evidence for external audits and regulatory inspections.
Using the audit log for compliance
The audit log is purpose-built to support the scenarios that matter most for governance and security teams.Security audits
Demonstrate a complete chain of custody for configuration changes. Every action is timestamped and attributed to a specific user or the system.
Access reviews
Confirm which users accessed or modified sensitive records during a given period. Filter by Resource → User and set a date window to pull a clean report.
Incident investigations
Reconstruct the sequence of events leading to an incident. Combine date, resource, and action filters to isolate the relevant entries and share them with your security team.
Regulatory obligations
Meet requirements under GDPR, SOC 2, ISO 27001, and similar frameworks that mandate a tamper-proof change history. The append-only log satisfies the immutability requirement out of the box.
