Review the Audit Log
Configuration changes and security events in your organization are recorded in the audit log, so you can check later when, who, and what happened.
Open “Organization Settings” from the account icon menu in the top right, go to the “Security” tab, and click “Open” under Audit Log.
Only admins can view the audit log. Records cannot be edited or deleted.
What Is Recorded
| Category | Examples |
|---|---|
| Organization | Organization name and currency changes, members joining, leaving, or changing roles, regenerating the invitation access key, permanently deleting Library assets |
| Contract | Seat changes, scheduling or reverting a cancellation, usage limit changes |
| Security | IP restriction setting changes, access from IP addresses that are not allowed, changes to the Japan-hosted model and model policy settings |
| Authentication | Successful and failed sign-ins, registering and removing passkeys |
| Account | Account deletion |
| Audit | Viewing the audit log and exporting it as CSV |
Filter the Log
Set “Category,” “Result,” “From,” and “To,” then click “Apply” to filter the entries. To see older entries, click “Load more” below the list.
The table shows the following columns.
| Column | Description |
|---|---|
| Date/Time | When the event happened |
| Event | What happened (such as before/after values or the source IP address) |
| Actor | The user who performed the action, or “System” for automated processes |
| Result | Success, Failure, Blocked, or Detected |
“Blocked” means a connection was rejected in the IP restriction’s block mode. “Detected” means a connection from outside the allow list was recorded in test mode (the connection was not rejected).
Export as CSV
Click “Export CSV” in the top right of the screen to export the audit log with the current filters as a CSV file. The export itself is also recorded in the audit log.