What it is
The Audit log (/audit) is the immutable (append-only) record of the tenant’s security and administration events. Nothing is ever edited or deleted. It answers who did what, when and from where.
What gets recorded
- Authentication: login (success, failure, lockout), logout, password change/reset, 2FA, detected token reuse, OTP.
- Users: invite, edit, role change, deactivation, unlock, import and the self-enrollment lifecycle (registration, approval, rejection).
- Tenants — creation, update, suspension.
- SCIM provisioning from Entra ID and Google.
- Risk automations cover auto-enrollment and alerts.
- Devices: agent device revocation.
Each event automatically captures the IP, the user-agent and, when a Super Admin is acting on behalf of the tenant, an impersonation mark.
The screen
A table with when, action (in human-readable language), actor and role, target, result (success/failure) and IP. You get:
- Filters for search, action, result and date range.
- CSV export, for archiving or external analysis.
- Detail — a modal with all fields of the event (user-agent, impersonation, IDs, metadata) and a copy button.
How to use it
- Investigate: “who changed this user’s role?”, “which IP did that failed login come from?”.
- Compliance — evidence of controls for internal and external audits.
- Security: spikes in login failures, token reuse and revocations help detect abuse.