What a row tells you
Categories
Every event belongs to exactly one of five planes, and the filter buckets by them.What Resource does not record
What Resource does not record
Private items are deliberately absent. These events also feed the shared activity feed, so
anything private stays out of both. Something that happened to a private file appears in
Governance if it was an ownership change, and nowhere otherwise.
What Governance covers in full
What Governance covers in full
- Invitations sent and cancelled. - Members joining and being removed, and roles changed. - Members added to and removed from a team, and people joining and leaving one. - Workspace settings and logo updated, and the 2-factor policy toggled. - Ownership transferred, including an admin taking ownership of a private item.
Exports audit themselves
Exports audit themselves
Exporting the log is itself an audited action under Security, and that row is written whether the export
completes, fails, or is abandoned partway.
Why Billing rows have no person
Why Billing rows have no person
Billing events are driven by the payment provider rather than by a member, so the Member
column shows the system.
Filtering
Four filters, and they combine.
To find everything done to someone, filter by category Governance and read the rows.
Exporting
Use Export to download the current view as CSV. The export honours the filters you have applied, so narrow the view first and you get exactly that slice. Large exports stream, so a wide date range does not have to be broken up by hand. Very large ones stop at a safety limit. If you are exporting a long period from a busy workspace and the row count looks suspiciously round, narrow the range and export in slices.Ownership transfers
Ownership changes are worth calling out, because they are the one place workspace administration reaches into a member’s private work. Two different things appear as Ownership transferred:- An admin or the workspace owner transfers a file, task board, or folder to another member.
- An admin claims an unassigned resource, usually something left behind by a departure. See Unassigned resources.
What it does not contain
The audit log is metadata only. It records that something happened, to what, and by whom, and never the contents of your work. No row ever holds:- The text of a workflow, playbook, or task board cell.
- Prompts, screenshots, or anything from a run, which stays on the device that ran it.
- Credentials, tokens, or plugin secrets.
- Values from your settings. A settings change records which keys changed, never what to.
A row can name a resource and count how many things an action touched. It cannot tell you what was inside them. To
know what a file contains, open the file.
Retention
The log is a record. Nobody can edit or delete an event, an admin included. Final account cleanup removes identifying details from active audit events while preserving the record of what happened. This cleanup begins 90 days after account closure. During the recovery window, those details remain. Archived events follow their separate retention schedule. About 13 months of history is available in the app. Older events are moved out of the live log, so export anything you need to keep beyond that.Related
Organization management
Members, roles, policies, and unassigned resources.
Ownership
Who owns a file, and how it changes hands.