Audit log
The audit log records every meaningful change in your organization: who did it, when, from which IP address, and what changed. Owners and Admins can browse it at /settings/audit-log.
What's recorded
One entry per action, written automatically — there is nothing to enable:
- Monitors, projects, status pages, walls — created, updated, deleted; wall kiosk-URL (token) rotations get their own
wall.token_rotatedentry. - Incidents — opened, acknowledged, resolved, deleted.
- Alert channels and maintenance windows — created, updated, deleted.
- Team members — added, role changed, removed.
- API keys — created and revoked.
- Billing — plan changes.
Each entry stores the actor (or "system" for automated actions such as incidents opened by checks), the request IP, and the changed attributes. Secrets — tokens, passwords, keys, channel configuration — are redacted before they are written, so they never appear in the log.
Filters and export
Filter the log by action type, team member, and date range. Export CSV downloads exactly what the current filter shows — handy for compliance reviews or archiving.
Visibility per plan
Your plan controls how far back you can see:
| Plan | Window |
|---|---|
| Free | Last 7 days |
| Pro | Last 30 days |
| Business & Agency | Last 365 days |
Upgrading immediately reveals older entries still within the retained year — nothing inside that window is lost while you're on a smaller plan.