Skip to main content
Sign in

Review the audit log

The audit log is a permanent record of who did what in your organisation. Use it to answer 'who changed this donor', 'when was that role granted', or 'who revoked that API key' - with the actor, outcome, and time for every event.

Together records an audit event for every state change and security event in your organisation: donor and donation edits, settings and user changes, API-key and webhook changes, sign-ins, and password or MFA changes. The record is append-only - events can't be edited or deleted - so it stands up as evidence long after the fact.

The audit log is on the Compliance add-on and the Enterprise plan. If you don't see it under Settings, an ADMIN can add it from Settings -> Billing. Recording happens for every organisation from day one; the add-on unlocks the ability to read it back.

Before you start

You need:

Open the log

Go to Settings -> Audit log. Events are listed newest first, showing:

Both successes and failures are recorded, and both people and automated systems appear as actors - a staff member's edit and a webhook-driven donation sit in the same timeline.

Filter the list

Three filters narrow the view, and they combine:

  1. Outcome. The pills at the top switch between all events, only Success, or only Failure - a quick way to surface everything that didn't complete.
  2. Action. The dropdown lists every action type. Pick one - say user.role_changed - to see only those events.
  3. Date range. Set From and To to bound the window to a specific day or period. Dates are read in your organisation's timezone, so "1 July" means your calendar day.

Press Apply to run the filters, or Clear to reset. The list paginates 50 events per page.

What the log is - and isn't

What to do next