Reviewing audit logs
Audit logs provide an immutable record of user and system activity. Use them to investigate configuration changes, support access reviews, and correlate administrative actions with operational events.
Review activity
- Open Settings > Organization > Audit Logs.
- Set the relevant date range and filters before searching broad periods.
- Review the actor, action, target, timestamp, and available event details.
- Export the filtered result when evidence must be shared or retained outside Studio.
- Correlate the event time with workflow traces and delivery issues.
Investigation practices
- Record timestamps with timezone and the filters used.
- Preserve the original export; perform annotations in a copy.
- Treat absence of an event as inconclusive until retention and event coverage are confirmed.
- Restrict exports because they may contain identities, resource names, and configuration context.
- Escalate unexpected privilege, security-profile, client-secret, MCP, or AI-governance changes.
note
Retention duration, export format, and the complete event catalog depend on the deployed service configuration. Confirm these operational details with your platform administrator.