Audit Logs

Track all significant actions within your workspace with a comprehensive audit trail. Audit logs provide full visibility into who did what and when, helping you maintain security, compliance, and accountability across your team.

Admin access required

Full administrative audit logs are an Enterprise capability and are available to workspace admins only. Other roles do not have access to this section. If you need audit log access, contact your workspace administrator.

What's Tracked

All significant actions within your workspace are automatically logged. The audit trail covers full CRUD on every operational resource plus channel-, session-, and account-level events. The full list of resources is:

  • Agents: create, update, delete, duplicate, publish, unpublish, archive, restore.
  • Tools: create, update, delete, and individual execute events.
  • Webhooks: create, update, delete, and outbound delivery events.
  • Knowledge bases & files: create, update, delete, upload, and import / export.
  • Phone numbers: import, update, assign, release, and unblock.
  • Campaigns: create, update, start, stop, pause, archive, delete.
  • Call logs & conversations: export and listen-in / take-over events.
  • Wallboards: create, update, delete, share-link mint and revoke.
  • Test suites: create, update, delete, and individual run (execute) events.
  • Post-call actions: create, update, delete, and configure.
  • Tickets: create, update, status changes, and assignment changes.
  • Members & roles: invite, role change, permission override, remove.
  • Integrations: connect, disconnect, secret rotate.
  • API keys: create, rotate, revoke, IP-whitelist changes.
  • Authentication: sign-in, sign-out, failed-login events (per-user IP and user-agent captured).
  • Billing: plan upgrades, downgrades, add-on requests, and payment method updates.

Each action is one of: CREATE · UPDATE · DELETE · CONNECT · DISCONNECT · ROTATE · EXECUTE · START · STOP · LOGIN · LOGOUT · EXPORT · IMPORT · ARCHIVE · RESTORE · PUBLISH · UNPUBLISH : applied to the relevant resource above.

Each audit log entry records the action performed, the resource type affected, the user who performed it (with their IP address and user agent string), the timestamp, and any field-level changes showing exactly what was modified.

Viewing Logs

The Audit Logs page opens with a set of summary stats cards at the top, giving you a quick overview of recent activity:

  • Total events: The total number of audit events recorded in the last 30 days.
  • Top action: The most frequently performed action type.
  • Top resource: The resource type with the most activity.
  • Active users: The number of distinct users who have performed logged actions.

Below the stats cards, a searchable and filterable table displays all audit events in reverse chronological order. Each row shows the action, resource, user, and timestamp at a glance.

Filtering

Use the filter controls above the table to narrow down the audit log:

  • Action type: Filter by specific actions such as "created", "updated", "deleted", or "connected".
  • Resource type: Show only events related to a specific resource like agents, users, or phone numbers.
  • User: View actions performed by a specific team member.
  • Free-text search: Search across all fields to find specific events by keyword.

The table supports pagination with configurable items per page; choose from 10, 25, 50, or 100 rows to match your preference.

Event Details

Click any event row to expand its full details. The detail view is organised into three sections:

  • Event info: The action type, resource type, resource name, and precise timestamp.
  • User info: The name and email of the user who performed the action, along with their IP address and user agent string.
  • Change diff: A field-by-field comparison showing the before and after values of any modified fields. This makes it easy to see exactly what changed, for example, an agent's system prompt being updated or a member's role being changed.

Data Retention

Audit logs are retained for 30 days. After this period, log entries are automatically cleaned up and permanently removed. If you need to keep audit data for longer, export the relevant records before they expire.

The 30-day retention window is rolling; new events are continuously recorded whilst events older than 30 days are pruned. This ensures the audit log remains performant and focused on recent activity.