Skip to content
HELP CENTER/ADMIN & ACCOUNT SETUP/READING THE AUDIT LOGUPDATED 15 AUG 2026

Reading the audit log

What is recorded, how to search it, and how to answer the questions an inspector actually asks.

Hendl Support · Updated 15 Aug 2026
On this page

Settings → Audit log. Administrators and Auditors only.

What is recorded

Every action that changes state or grants access:

  • Case created, moved stage, reassigned, closed, reopened
  • Correspondence sent, documents added or removed
  • Digital worker actions, including which autonomy level applied at the time
  • Approvals given and refused, with the approver
  • Role, team and permission changes
  • Autonomy level changes, with the reason given
  • Sign-ins, and failed sign-in attempts
  • Integration connections and disconnections

Entries cannot be edited or deleted by anyone, including Administrators.

What is not recorded

Reads. Opening a case is not logged, so the audit log cannot answer "who looked at this". That is a deliberate scope decision, and worth knowing before somebody asks.

Searching it

Filter by date range, person, case, or action type. The case-scoped view is usually what you want: open the case and choose History for that case's entries only, in context.

The three questions inspectors ask

"Who decided this, and when?" Filter to the case and look for the approval entry. It names the person, the timestamp and what they approved.

"Was this decided by a human or by a machine?" Every action carries its actor. Digital worker actions additionally record the autonomy level at the time, which answers the follow-up before it is asked.

"When did you change your policy, and why?" Filter to autonomy and configuration changes. The reason field is required precisely so this question has an answer.

Retention

Audit entries are retained for the life of the workspace and are not affected by closing or archiving a case.

Did this answer your question?
More in Admin & account setup