Skip to main content

Audit log

The audit log is a running record of what happened in your workspace and who did it: sign-ins, device changes, member changes, and settings changes. It is the place to go when you need to answer "who changed this, and when?", for example if a device goes missing and you need to see whether someone removed it.

The audit log is read-only. Nothing in it can be edited or deleted, so it stays trustworthy as a record.

Permission required: Workspace Admin.

Opening the audit log

Click your name in the top-right, then Settings, and open the Audit log tab. The tab only appears if you're a Workspace Admin; Operators and Viewers don't see it.

What gets recorded

The log captures the actions that matter for accountability, including:

  • Sign-ins, both successful and failed, so you can see who accessed the workspace and when.
  • Device changes, such as a device being registered, assigned, edited, or deleted.
  • Gateway changes, the same set of actions for gateways.
  • Member changes, such as an invite being sent, a role being changed, or a member being suspended or removed.
  • Settings changes, such as security or workspace settings being updated.

Each entry records the person who did it, the exact time, and the details of what changed.

Reading an entry

Each row shows:

  • When the action happened, in your timezone.
  • Who did it (their name and email). System-generated actions show as "System". When platform support acknowledges an alarm or changes a workflow on your behalf (enable, disable, snooze), the entry shows the actor as Platform support: the event is always on the record, without exposing an individual support operator.
  • Action, a plain-language description with a colored tag for the kind of action (Auth, Change, Action, or Info).
  • Item, the kind of thing affected (a device, a gateway, a user, and so on).

Click Details on any row to open a panel with everything recorded for that entry: the full action, who did it, the item affected, the IP address and device the action came from, and a structured breakdown of exactly what changed.

The record survives deletion

When something is deleted, its key details are copied into the audit entry at the moment it happens. So even after a device is gone, its details (such as its name and DevEUI) are still there in the matching Device deleted entry. This is what lets you confirm what was removed and by whom.

Finding what you need

For a busy workspace the log can be long. Narrow it down with the controls along the top:

  • Search by action or by person's name or email.
  • Type filter: Auth, Changes, Actions, or Info.
  • Item filter: Devices, Gateways, Users, and so on.
  • Date range: pick a start and end date, or use a preset like Last 7 days or Last 30 days.

The filters combine, so you can ask a precise question like "device changes in the last 30 days" and page through just those results.

Exporting

Click Export CSV to download the entries currently shown (with your filters applied) as a spreadsheet file. This is useful for keeping a copy as evidence, or for sharing a record with someone who doesn't have access to the workspace.

Frequently asked

Can anyone change or remove an entry? No. The audit log is append-only and read-only for everyone. That's what makes it reliable as a record.

Why can't an Operator or Viewer see the tab? The audit log is limited to Workspace Admins because it can reveal sensitive activity, such as who signed in and when.

How far back does it go? The log keeps your workspace's history; there's no automatic cut-off. Use the date range to focus on the period you care about.