Skip to main content
The audit log is your workspace’s record of consequential actions. It answers “what happened, and who did it”. Admins and the workspace owner can read and export it. Members cannot. Open the workspace menu at the top of the sidebar, choose Workspace settings, then Audit log.

What a row tells you

Categories

Every event belongs to exactly one of five planes, and the filter buckets by them.
Private items are deliberately absent. These events also feed the shared activity feed, so anything private stays out of both. Something that happened to a private file appears in Governance if it was an ownership change, and nowhere otherwise.
  • Invitations sent and cancelled. - Members joining and being removed, and roles changed. - Members added to and removed from a team, and people joining and leaving one. - Workspace settings and logo updated, and the 2-factor policy toggled. - Ownership transferred, including an admin taking ownership of a private item.
Exporting the log is itself an audited action under Security, and that row is written whether the export completes, fails, or is abandoned partway.
Billing events are driven by the payment provider rather than by a member, so the Member column shows the system.
Connector rows name the plugin and the connection, never the credentials, which stay on the server.

Filtering

Four filters, and they combine. To find everything done to someone, filter by category Governance and read the rows.

Exporting

Use Export to download the current view as CSV. The export honours the filters you have applied, so narrow the view first and you get exactly that slice. Large exports stream, so a wide date range does not have to be broken up by hand. Very large ones stop at a safety limit. If you are exporting a long period from a busy workspace and the row count looks suspiciously round, narrow the range and export in slices.

Ownership transfers

Ownership changes are worth calling out, because they are the one place workspace administration reaches into a member’s private work. Two different things appear as Ownership transferred:
  • An admin or the workspace owner transfers a file, task board, or folder to another member.
  • An admin claims an unassigned resource, usually something left behind by a departure. See Unassigned resources.
The Resource column names the item either way. Claiming a folder is one entry naming the folder, covering everything ownerless inside it, rather than an entry per file. Both are deliberate acts by a person, and both are recorded before they take effect. If the record cannot be written, the transfer does not happen. See Ownership.

What it does not contain

The audit log is metadata only. It records that something happened, to what, and by whom, and never the contents of your work. No row ever holds:
  • The text of a workflow, playbook, or task board cell.
  • Prompts, screenshots, or anything from a run, which stays on the device that ran it.
  • Credentials, tokens, or plugin secrets.
  • Values from your settings. A settings change records which keys changed, never what to.
A row can name a resource and count how many things an action touched. It cannot tell you what was inside them. To know what a file contains, open the file.

Retention

The log is a record. Nobody can edit or delete an event, an admin included. Final account cleanup removes identifying details from active audit events while preserving the record of what happened. This cleanup begins 90 days after account closure. During the recovery window, those details remain. Archived events follow their separate retention schedule. About 13 months of history is available in the app. Older events are moved out of the live log, so export anything you need to keep beyond that.

Organization management

Members, roles, policies, and unassigned resources.

Ownership

Who owns a file, and how it changes hands.