Skip to main content
Audit Log records administrative and security activity for your organization. Use it to investigate who changed a provider connection, key, membership, policy, or other configuration. Access and export permissions are separate and follow your role and plan.

Investigate a change

  1. Open Audit Log and choose the time period.
  2. Search for the relevant action or resource and narrow by category or outcome.
  3. Use Evidence filters for the actor, affected user, resource, changed field, reason, or request ID.
  4. Open an event to inspect the recorded actor, action, outcome, and safe change metadata.
Secrets, provider credentials, and model transcripts do not belong in audit event details. Use Activity for model requests and MCP Activity for external tool executions.

Export evidence

With audit export permission, choose CSV or JSONL and select Download. The export uses the current filters. Preserve the downloaded evidence and its digest according to your organization’s handling policy, and review the displayed verification result before relying on an export for an investigation. The audit trail describes recorded events and their evidence. It does not by itself establish legal compliance or replace your organization’s access reviews. Where audit identity erasure is enabled, an event can retain its integrity evidence after its personal details are removed. The dashboard labels it Identity erased. Searching for the removed name or email no longer finds that event; use its remaining time, action and outcome.