Skip to main content

Overview

The Audit Log provides a record of security and administrative actions taken across your organization. It tracks who did what, when, and to which resource. Organization administrators can access the audit log from the Settings page under the Audit Log tab.

Viewing the Audit Log

From the left sidebar, click on Settings, then select the Audit Log tab. Each entry in the log includes:
  • Time: When the action occurred
  • Actor: The user or system that performed the action
  • Action: What was done (e.g., “Created role”, “Provisioned user”)
  • Category: The area the action belongs to (e.g., Auth, RBAC, SCIM)
  • Resource: The resource that was affected, along with its type and ID
Click any row to open a detail panel with the full event information, including the actor’s ID, auth method, IP address, and any additional metadata. The audit log supports several ways to narrow down events:
  • Search: Free-text search across actor email, action, category, resource type, resource ID, and event details
  • Category filter: Filter by category (e.g., Authentication, SCIM Provisioning, Roles & Permissions)
  • Action filter: Filter by specific action. When a category is selected, only actions relevant to that category are shown
  • Date range: Filter by time window (Today, Last 7 Days, Last 30 Days, Last 90 Days)
Filters can be combined. For example, you can search for a specific user’s email while filtering to the SCIM category and the last 7 days.

Categories and Actions

Authentication

Actions related to user login, logout, and identity provider configuration.

Member Management

Actions related to adding or removing organization members.

Roles & Permissions

Actions related to roles, role assignments, permissions, service accounts, and API keys.

Connectors

Actions related to data source connectors.

Organization Settings

Actions related to organization-level configuration.

API Access Keys

Actions related to API access keys used for programmatic access.

Secrets

Actions related to organization secrets.

SCIM Provisioning

Actions related to SCIM-based user and group provisioning. Token and OAuth client management actions are performed by organization administrators through the UI. User and group provisioning actions are performed automatically by your identity provider via the SCIM API.

Library

Actions related to the organization’s shared library being materialized into sandbox environments.

Data Retention

Audit log entries are retained and available for querying as long as your organization is active. The log is automatically refreshed every 30 seconds while the tab is open, and pauses when the browser tab is not visible.