Audit log

An append-only record of who signed in, who changed access, and who created or deleted what.

The audit log records security-relevant actions across the installation. Instance administrators open it under Admin → Audit log.

Each entry has the time, the person who acted, what they did, what it was done to, their IP address, and details such as the old and new role in a role change. Filter by kind of event, date range or person — Filter by this actor on any row narrows the log to one person — and use Export CSV to take the result into your own tools.

What’s recorded

AreaEvents
Sign-inSign-ins and sign-outs, password changes and resets, email confirmation, linking an external identity.
AccountsSignups, profile changes, account deactivation and deletion.
MembersMembers added, invited and removed, invitations accepted, cancelled and resent, role changes.
Flow sharingAccess to a flow granted, changed or revoked.
API tokens and SecretsCreated, updated, revoked or deleted.
WorkspacesCreated, renamed or deleted.
FlowsCreated or deleted, published or unpublished as a public example, versions saved, restored or deleted.
Datasets and AssetsDatasets created or deleted, assets deleted.
Instance administrationAccounts created, changed, deactivated and reactivated by an administrator, instance roles, passwords set by an administrator, sign-in providers added, changed or removed, node library refreshes, plan changes.

The log never stores passwords, tokens, secret values or request bodies.

How it behaves

  • Append-only. Entries can’t be edited or deleted from the app.
  • Recorded while it’s on. The audit log is part of paid plans, and events are recorded while the plan includes it. Turning it on later doesn’t fill in what happened before.