Reading the audit log
What is recorded, how to search it, and how to answer the questions an inspector actually asks.
On this page
Settings → Audit log. Administrators and Auditors only.
What is recorded
Every action that changes state or grants access:
- Case created, moved stage, reassigned, closed, reopened
- Correspondence sent, documents added or removed
- Digital worker actions, including which autonomy level applied at the time
- Approvals given and refused, with the approver
- Role, team and permission changes
- Autonomy level changes, with the reason given
- Sign-ins, and failed sign-in attempts
- Integration connections and disconnections
Entries cannot be edited or deleted by anyone, including Administrators.
What is not recorded
Reads. Opening a case is not logged, so the audit log cannot answer "who looked at this". That is a deliberate scope decision, and worth knowing before somebody asks.
Searching it
Filter by date range, person, case, or action type. The case-scoped view is usually what you want: open the case and choose History for that case's entries only, in context.
The three questions inspectors ask
"Who decided this, and when?" Filter to the case and look for the approval entry. It names the person, the timestamp and what they approved.
"Was this decided by a human or by a machine?" Every action carries its actor. Digital worker actions additionally record the autonomy level at the time, which answers the follow-up before it is asked.
"When did you change your policy, and why?" Filter to autonomy and configuration changes. The reason field is required precisely so this question has an answer.
Retention
Audit entries are retained for the life of the workspace and are not affected by closing or archiving a case.