Skip to content

The audit log is an append-only record of privileged actions in your organization — who did what, to which resource, and when.

Where to find it: Governance → Audit logs

Everyone can open it. What you see depends on one permission, View audit log (audit:view):

  • With it, you see every event in the organization. Built-in Org Owner, Org Admin, and the free Auditor role include it.
  • Without it, the tab is called Your activity. You see what you did, plus what happened on connections you own or can edit, including tool calls other people made through them. This is every other role: People Admin, Team Admin, Member, Billing Admin, Guest, and custom roles. You can also open it from Settings → Your activity, or from View activity on a connection you own or can edit.

Anyone who can edit a connection — you own it, or it was shared with you at the Edit level, directly, through a team, or with the whole organization — sees every member's tool calls made through that connection, not only their own. This is intended: editing a connection includes seeing what happened on it. People who can only use or view it do not see other people's calls. If access is removed, those rows disappear the next time the page loads.

If you own or can edit a very large number of connections, Your activity lists only what you did yourself and says so. Open View activity on a connection to see everything on that one connection.

The log records meaningful changes and tool calls — not every page view.

What gets recorded

From the product surface, expect coverage across:

Area Examples of what’s captured
Membership & access Invites, member role changes, removals, roles, teams, restrictions, SSO/SCIM changes
Connections Connect, reconnect, transfer, delete (including transfers during offboarding)
Connectors Custom connector authoring and related changes
Toolboxes Create/update/share and related toolbox activity; synthetic tools
MCP Client grants on the MCP endpoint, and mcp.tool_called (tool, connection, status, duration)
Assistant Provider key changes and other assistant admin actions
Organization Org/team/billing-class events
Logging Observability destination configuration

Each entry typically includes the actor, action, resource, time, and metadata you can open for full detail.

Categories in the UI

The Audit logs tab groups events for filtering:

Category What it groups
Authentication Sign-in and account-security events
Assistant Assistant-related actions
MCP Your organization's MCP endpoint and tool calls
Toolboxes Toolboxes and synthetic tools
Connections Connections and connectors
Access Members, invites, roles, SSO/SCIM, restrictions
Org Organization, teams, billing-class events
Other Anything that doesn’t match the above

Find an event

  1. Open Governance → Audit logs.
  2. Use search for an action name, actor, resource, or metadata text.
  3. Narrow with the type filter (the categories above). Counts show how many loaded events fall in each bucket.
  4. Select a row for the full detail panel.

You'll know it worked when: You can explain what changed, who changed it, and when.

Beside the category filter you also get:

Filter Choices
Date range All time, Last 24 hours, Last 7 days, Last 30 days
Action kind Created, Updated, Deleted, Other
Actor One member, searched by name or email

Search and filters sync into the URL (q, category, range, actor, action), so you can bookmark or share a view. You can also export the filtered range. Refresh reloads the log from the server.

Forward events elsewhere

To send classified events (tool_call / auth / admin) to your own observability stack, configure destinations under Settings → Logging (permission logging:manage). Datadog delivery is supported; see Forward audit events.

Good to know

  • The log is append-only and scoped to the current organization.
  • MCP tool calls are audited even when they succeed — useful when investigating what an agent actually ran.
  • Retention and which advanced logging features you get depend on your plan; workspace audit access itself is part of the standard Gold/Black workspace feature set.