Activity Log
6 min
the activity log is a chronological record of every request, approval, and rejection across your organisation it records every action taken, and it is read only each entry describes one event, something requested, approved, rejected, or applied, and identifies what it happened to, who did it, and when note the activity log visibility on ui is enabled only for the admin/owners of the org when to use it you'll typically open the activity log to answer a specific question, such as what happened to our account around a specific time (for example, while investigating a security incident) who approved a particular transaction, vault, or policy change why a user's access or a contact's status changed whether a request was approved, rejected, or is still pending where to find it activity log is in the left hand navigation, below automations how it works before using the log, it helps to understand two things about how entries are structured each entry is about an entity, not about the request that changed it an entity is the thing being acted on it could be a transaction, a vault, a user, a contact, and so on when you open an entity's row, the entity column links you straight to that record some actions require approval, and appear as a chain of related entries certain actions like creating a vault, adding a policy rule, deactivating a user cannot take effect immediately they go through an approval step first when this happens, the activity log records each stage separately requested → approved → applied if a request is turned down instead requested → rejected if more than one approval is required, each approver's decision is logged as its own entry this means one approval gated change can appear as three or four related rows instead of one and you can see not just that something happened, but who asked for it and who signed off other actions don't need approval at all, because there's no intent to confirm for example resending an invite transaction moving to its next processing step once it's already been approved these are logged directly, as a single entry reading an entry each row has six columns column information time when the event was recorded activity what happened, in plain language (for example, "transaction approved") entity what the action was taken on click through to open that record directly user who performed the action blank for a small number of system generated events outcome whether the system processed this step correctly metadata the platform (web, ios, api, etc ) and ip address the action came from filtering activity you can filter by activity, entity type, user, outcome, platform, and time range, and combine filters to narrow results open all filters to see every option next steps for the exact wording you'll see for every entity and action, see the event reference below