Reviewing the audit log
The audit log records who did what, on which record, and when, with the values before and after a change. This page shows how to find the entry you need and read it.
Open Administration › Audit Logs. You need view_audit_logs; Internal Auditors and ICT Administrators have it. The log is read-only: nobody can edit or delete entries from the suite.
What is recorded
- Sign-in and sign-out.
- Changes to records: creating, updating and deleting users, units, roles, request templates, voucher types, memo templates, documents, events, assets and so on.
- Permission changes, recorded separately from other user updates.
- Work decisions: requests created, approved, rejected, commented on; payments approved or rejected; memos; leave.
- Settings changes, including modules, appearance and terminology.
- Mail sent and mailbox administration.
- AI assistant activity: runs, tool steps and approvals of AI actions.
- Bulk jobs such as the nominal roll import (
USER_BULK_IMPORT).
Each entry stores the person as they were at that moment (name, email, role, units), so it still reads correctly after they change job or leave.
Find an entry
- Search the description, the person's name or email.
- Filters: Entity types (what kind of record), Action types (what was done), Statuses (Success only or Failed only) and a date range.
- An entry. Newest first. Columns: Timestamp, User, Action, Entity, Description and Status. Select a row to open it.
Read an entry
An entry's page shows:
- Status
- Whether the action succeeded.
- User
- Name, email, role and units of the person who did it.
- Entity
- The type of record and its ID.
- IP Address / User Agent
- Where the action came from and the browser used.
- Data Snapshots
- Previous Data and New Data: the record before and after the change, as JSON.
Common questions
Who changed this person's permissions?
- Open the person in Users and select the Logs tab. It lists the last 50 entries about them.
- Look for a Permission Changed entry and open it. Compare Previous Data with New Data.
Who approved or rejected a request?
The request's own page shows its full approval trail, which is usually quicker. In the log, filter Action types to Request Approved or Request Rejected and search for its reference.
When was a setting changed?
Filter Action types to Setting Changed, and use the date range.
Were there failed actions?
Set Statuses to Failed only.
Filters and search are kept in the page address. Copy the address to share exactly what you are looking at with a colleague who also has access.
There is an export_audit_logs permission, but the Audit Logs screen does not have an export button yet.