Admin console
Audit
The chronological record of every meaningful action — the system of record for "who did what, and when."
Admin → Audit is the chronological feed of actions people and systems take in your organization. It's the system of record when you need to answer who did what, and when. Only the Owner and Admin roles can see it.
What each row shows
- Time — when it happened, shown in your device's time zone.
- Action — the action type, as a short colored label.
- User — the email of whoever took the action (system actions show
-). - Target — the resource type and the start of its ID.
- Details — the first part of the event's data.
- IP — where the action came from.
Filtering
- Action type — narrows to one action from the list. For an action that isn't in the list, use All actions; the Action column shows it as a code, such as
team.member_add. - Search users — partial match on email.
- Start date, End date — set the period to look at, as days in your device's time zone. The whole end date is included.
- Include routine system logs — also shows the recurring entries hidden by default (records of the audit screen being viewed, and of access sync runs).
- Refresh — reloads the latest entries with the current filters.
Changing a filter takes you back to the first page; each page holds 50 rows.
Common situations
- Someone's role changed — pick Role changed in Action type and narrow the period with Start date and End date. User is the person who made the change, and Target is the start of the ID of the account whose role changed. In Search users, enter the email of the person who made the change, not the person whose role changed. Accounts being activated or deactivated are under Account status changed.
- Failed logins are rising — pick Login failed in Action type, set Start date and End date, then scan the User (the email that was tried) and IP columns.
- Feeding a SIEM — the audit screen itself only offers filters, pages, and refresh; there's no export button. If you need to connect an external log system, check with your platform team about the log or API paths.
Allowed and denied DB queries, and what was masked in them, are in the Query audit log at the top right of the screen. Click a row to open Query details. The Export CSV and Export JSON icons download the most recent entries, up to 10,000, as a file; the on-screen filters don't apply to them.