Audit log
The audit log is a read-only record of what happened in an account and who did it: sign-ins, device and gateway changes, member changes, and settings changes. It is the place to go when a customer says a device has gone missing and you need to see whether someone removed it, and who.
The audit log works the same for you as it does for your customers, so the full how-to, what gets recorded, reading an entry, filtering, and exporting, lives in the end-user guide: Audit log. This page covers the parts that are specific to you: the roll-up across sub-accounts, and viewing a single customer's log.
Open it from your name in the top-right, then Settings, and the Audit log tab. It is limited to admins; Operators and Viewers don't see it.
A roll-up across your sub-accounts
At your own level the audit log is a roll-up: it shows activity across your workspace and every sub-account beneath it, with an Account column telling you which account each entry belongs to. "Top level" means the entry happened in your own workspace rather than in a sub-account.
This is what lets you investigate a customer's report without first knowing which sub-account is involved. For the missing-device case, filter by Item: Devices, set a Date range around when the customer last saw it, and look for a Device deleted entry. The entry names who did it, when, the account it happened in, and (because the device's details are copied into the entry at deletion) what was removed.
Viewing one customer's log
To focus on a single customer, act as that sub-account (the Act as switcher), then open Settings → Audit log. Scoped in, the log shows only that account's activity and drops the Account column, since every entry belongs to the one account.
Exporting for a dispute
Export CSV downloads the entries currently shown, with your filters applied. Use it to keep a copy as evidence, or to share a record with a customer. The export respects the same scope you're viewing: the roll-up at your level, or a single account when you're acting as a sub-account.