Audit log

The append-only record of everything that matters — logins, user changes, provisioning and automations.

What it is

The Audit log (/audit) is the immutable (append-only) record of the tenant’s security and administration events. Nothing is ever edited or deleted. It answers who did what, when and from where.

Audit log in the qlture dashboard
Audit log: when, action, actor, target, result and IP — with filters, CSV export and per-event detail.

What gets recorded

  • Authentication: login (success, failure, lockout), logout, password change/reset, 2FA, detected token reuse, OTP.
  • Users: invite, edit, role change, deactivation, unlock, import and the self-enrollment lifecycle (registration, approval, rejection).
  • Tenants — creation, update, suspension.
  • SCIM provisioning from Entra ID and Google.
  • Risk automations cover auto-enrollment and alerts.
  • Devices: agent device revocation.

Each event automatically captures the IP, the user-agent and, when a Super Admin is acting on behalf of the tenant, an impersonation mark.

The screen

A table with when, action (in human-readable language), actor and role, target, result (success/failure) and IP. You get:

  • Filters for search, action, result and date range.
  • CSV export, for archiving or external analysis.
  • Detail — a modal with all fields of the event (user-agent, impersonation, IDs, metadata) and a copy button.

How to use it

  • Investigate: “who changed this user’s role?”, “which IP did that failed login come from?”.
  • Compliance — evidence of controls for internal and external audits.
  • Security: spikes in login failures, token reuse and revocations help detect abuse.

Email and adoption metrics
Portal overview