> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open.cx/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit logs overview

> See every sign-in, sign-out and change in your workspace, and who made it. Read this to review access, investigate a change or export the trail.

The audit log records who did what in your workspace, and when. It covers teammate sign-ins and sign-outs, and every change to settings, roles, API keys, AI training, integrations and sessions.

## Who can see it

Only roles with the **Audit logs** permission can open the audit log. The permission is read-only: nobody can edit or delete an entry. The Admin role has it by default. To give it to another role, open **Settings → Roles**, edit the role, and turn on **Audit logs**.

## Open the audit log

Go to **Settings → Security** and scroll to **Audit Logs**. The newest events are at the top, and more load as you scroll.

Each row shows:

* **Actor** — the teammate, API key, Companion, mini-app or automation that acted
* **Event** — what happened, for example *Signed in with Google* or *Updated workflow*
* **Target** — what it happened to. For sign-ins and sign-outs, this is the teammate and the IP address
* **When** — how long ago, and the exact time on hover

Click a row to open its details: the full timestamp, the IP address and device, sign-in details, and a before/after table of what changed.

## Filter the log

Combine any of these filters:

* **Event** — all events, only sign-ins and sign-outs, or one area such as Security or Settings
* **Actor type** — people, the system, or API keys
* **Person** — one teammate: everything they did, plus the sign-outs the system ended for them
* **Date range** — one or more whole days

## Sign-ins and sign-outs

Every time a teammate signs in, the audit log records how they signed in: Google, Microsoft, single sign-on, partner access or password. It also records their IP address and browser.

Every time a teammate stops being signed in, the log records why:

| Reason                               | What happened                                                        |
| ------------------------------------ | -------------------------------------------------------------------- |
| Signed out                           | The teammate signed out                                              |
| Session expired                      | The sign-in reached its expiry and the teammate had to sign in again |
| Session revoked                      | The sign-in was ended before it expired                              |
| Removed from the workspace           | An admin removed the teammate, which signs them out everywhere       |
| Removed by the identity provider     | Your identity provider deprovisioned the teammate                    |
| Deactivated by the identity provider | Your identity provider deactivated the teammate                      |

A teammate who belongs to several workspaces shows up in the audit log of each one. Removing a teammate signs them out everywhere: the workspace that removed them sees *Removed from the workspace*, and their other workspaces see *Session revoked*. An expired sign-in is recorded the next time that browser opens the dashboard.

## Read the log over the API

Use [List audit logs](/api-reference/audit-logs/list) to export the trail or feed it into your own security tools. The API key needs the `audit-logs:read` scope. The Companion and the MCP `get_audit_logs` tool read the same log.
