Audit trail
Every action that changes something is recorded with the user, the time and the IP address it came from. It is the answer to "who did that?" and to an auditor's "show me".
Where #
Audit Trail in the console, scoped to the customers you can see. Newest first, with the event, the actor, the customer and a detail line; search narrows it.
What is recorded #
| Area | Events |
|---|---|
| Accounts | Sign-up, social sign-up, password change and reset, admin-set password, MFA enabled and reset, user created, updated, deleted |
| Customers | Customer created, updated, status changed (suspended, reactivated), cloud credits granted, migrations scheduled and cancelled |
| Agents | Registered (by token or by user), reattached, replaced, deactivated, reactivated, enrolled elsewhere; deployment token created and revoked |
| Jobs | Created, updated, deleted, started, cancelled; per-file upload and failure events on runs |
| Storage | Target created, updated, deleted; archiving switched on/off; archive rule set and removed |
| Cloud drives | Drive updated (mounted, changed, removed) |
| Access keys | AI key created and revoked; cloud worker keys created and revoked |
| Connectors | Microsoft 365 and Google Workspace archives and restores started |
| Billing | Subscription started and cancelled, payment set-up, auto-pay changed, invoice paid now, trial reuse flagged |
Actions taken through an AI access key or the API are attributed to the key's owner, exactly as if they had used the console.
Retention #
Audit events are kept for the life of the account and 90 days after it closes. They are not editable.