# Read the audit log

> Source: https://elaichi.ai/docs/guides/governance/read-the-audit-log/

The audit log is an append-only record of privileged actions in your organization — who did what, to which resource, and when.

**Where to find it:** **Governance → Audit logs**

Everyone can open it. What you see depends on one permission, **View audit log** (`audit:view`):

- **With it**, you see every event in the organization. Built-in **Org Owner**, **Org Admin**, and the free **Auditor** role include it.
- **Without it**, the tab is called **Your activity**. You see what you did, plus what happened on connections you own or can edit, including tool calls other people made through them. This is every other role: **People Admin**, **Team Admin**, **Member**, **Billing Admin**, **Guest**, and custom roles. You can also open it from **Settings → Your activity**, or from **View activity** on a connection you own or can edit.

Anyone who can **edit** a connection — you own it, or it was shared with you at the **Edit** level, directly, through a team, or with the whole organization — sees every member's tool calls made through that connection, not only their own. This is intended: editing a connection includes seeing what happened on it. People who can only **use** or **view** it do not see other people's calls. If access is removed, those rows disappear the next time the page loads.

If you own or can edit a very large number of connections, **Your activity** lists only what you did yourself and says so. Open **View activity** on a connection to see everything on that one connection.

The log records meaningful changes and tool calls — not every page view.

## What gets recorded

From the product surface, expect coverage across:

| Area | Examples of what’s captured |
| --- | --- |
| **Membership & access** | Invites, member role changes, removals, roles, teams, restrictions, SSO/SCIM changes |
| **Connections** | Connect, reconnect, transfer, delete (including transfers during offboarding) |
| **Connectors** | Custom connector authoring and related changes |
| **Toolboxes** | Create/update/share and related toolbox activity; synthetic tools |
| **MCP** | Client grants on the MCP endpoint, and `mcp.tool_called` (tool, connection, status, duration) |
| **Assistant** | Provider key changes and other assistant admin actions |
| **Organization** | Org/team/billing-class events |
| **Logging** | Observability destination configuration |

Each entry typically includes the **actor**, **action**, **resource**, **time**, and **metadata** you can open for full detail.

## Categories in the UI

The Audit logs tab groups events for filtering:

| Category | What it groups |
| --- | --- |
| **Authentication** | Sign-in and account-security events |
| **Assistant** | Assistant-related actions |
| **MCP** | Your organization's MCP endpoint and tool calls |
| **Toolboxes** | Toolboxes and synthetic tools |
| **Connections** | Connections and connectors |
| **Access** | Members, invites, roles, SSO/SCIM, restrictions |
| **Org** | Organization, teams, billing-class events |
| **Other** | Anything that doesn’t match the above |

## Find an event

1. Open **Governance → Audit logs**.
2. Use **search** for an action name, actor, resource, or metadata text.
3. Narrow with the **type** filter (the categories above). Counts show how many loaded events fall in each bucket.
4. Select a row for the full detail panel.

**You'll know it worked when:** You can explain what changed, who changed it, and when.

Beside the category filter you also get:

| Filter | Choices |
| --- | --- |
| **Date range** | All time, Last 24 hours, Last 7 days, Last 30 days |
| **Action kind** | Created, Updated, Deleted, Other |
| **Actor** | One member, searched by name or email |

Search and filters sync into the URL (`q`, `category`, `range`, `actor`, `action`), so you can bookmark or share a view. You can also export the filtered range. Refresh reloads the log from the server.

## Forward events elsewhere

To send classified events (`tool_call` / `auth` / `admin`) to your own observability stack, configure destinations under **Settings → Logging** (permission `logging:manage`). Datadog delivery is supported; see [Forward audit events](/guides/settings/logging).

## Good to know

- The log is **append-only** and scoped to the current organization.
- MCP tool calls are audited even when they succeed — useful when investigating what an agent actually ran.
- Retention and which advanced logging features you get depend on your plan; workspace audit access itself is part of the standard Gold/Black workspace feature set.

## Related

- [Set connector and tool restrictions](/guides/governance/set-restrictions)
- [Forward audit events](/guides/settings/logging)
- [Roles and permissions](/guides/members/roles)
