Skip to content

Read the audit trail

Screen /audit · Roles: Admin, Auditor

Every state change in the workspace - a verified payment, a role change, a released code - writes an audit row as it happens. Audit is where you read them, and it is the first stop when something surprising happened: the answer is always recorded.

The Audit screen - the event table with its action and entity filters

Four columns - When · Actor · Action · Entity - all sortable, with two filter boxes (action and entity type) and pagination. Click Details on any row for the whole event: who (and their actor type), what, the record it touched by name, the concrete field changes, and the IP address and browser it came from. Copy event puts that same trimmed view on your clipboard for a support ticket.

  • A person shows their name, with their actor type underneath.
  • system means an automation acted: an agent rule, a sweep, a scheduled job. The event carries the rule that acted, so “who sent that?” has an answer even when the answer is “the rule you configured.”
  • The window. The screen shows the most recent events and says how many (“Most recent 100 events”). Filtering happens inside that window - an empty result for an old search means you have looked past the window’s edge, not that the event never happened.
  • The hash-chain pill. Each event is chained to the previous one, and the pill says Hash chain intact when the trail verifies. You are entitled to know your own log is tamper-evident, not just to be told so.