Audit log & CSV export

Inspect administrative actions and export a bounded, filtered record for your team’s review.

On this page

The administrative audit log records workspace changes such as invitations, role updates, risk reviews, and device operations. It is separate from the agent Activity feed and the local collector's event export.

Filter the audit log

Open Audit log and narrow results using action, actor, and date filters. Review timestamps, actor identity, target, and available metadata. Use pagination to move through the filtered list.

A risk review or reopening is an administrative event. An agent's tool proposal is activity evidence. Use both views when answering who changed a setting and what the assistant subsequently requested.

Export matching records

Owners, administrators, and auditors can use the CSV export control. Security managers can read the log but do not have audit:export. The export uses the selected filters and includes up to 5,000 matching records.

For a larger investigation, narrow the date ranges and preserve the ranges alongside each downloaded file. Do not assume one CSV contains the installation's complete audit history.

Interpret completeness

Audit intent can be recorded before an external provider mutation and its outcome afterward. A timeout or missing outcome requires inspection of the provider; it does not prove that dispatch failed. Preserve the intent or operation ID for follow-up.

For MDM, the service's durable operation ledger and response journal contain additional command-delivery context. A CSV audit export is not a replacement for device receipts or provider acknowledgements.

Retain evidence appropriately

The application does not expose audit update/delete operations, but a database administrator can alter the backing records. The implementation does not provide WORM storage or database-enforced immutability. Protect exported evidence and audit storage using your organization's access and backup controls.

Self-hosted event and audit history have no automatic retention-deletion job. Plan an explicit retention process, preserve relevant evidence, and test restore procedures. An audit export can support a review; it does not by itself establish regulatory compliance or successful endpoint enforcement.

Explore the docs