The audit log is the permanent record of who did what in your business — role changes, refunds, deletions, permission edits, and every other sensitive action, each stamped with the person and the time. Open it from Settings → Compliance & data → Audit log.
Who can see the audit log?
Access is its own capability — audit — view — not a role tier. That means a compliance reviewer can be granted read access to the log without being made an admin. The full-page log at /settings/audit is additionally admin-gated.
How do I find a specific change?
The log is filterable from every angle:
| Filter | Use it to answer |
|---|---|
| Entity type | "Show me everything that happened to gift cards" |
| Action | "Show me every deletion" |
| Team member | "What did this person change?" |
| Client | "Everything that touched this client's record" |
| Severity | Info, notice, or critical — the shortlist worth reviewing |
| Date range | Bound the search to the period in question |
Open the log
Settings → Compliance & data → Audit log.
Narrow it down
Combine filters — a team member plus a date range plus an action gets you from "50 pages" to "the six entries that matter".
Open an entry
Each entry shows who, what, and when. Where a record was changed, the diff viewer shows the before and after values side by side, so "someone edited the price" becomes "changed from $120 to $90".
Can audit entries be edited or deleted?
No. The log is append-only by design and is not touched by your data-retention purge — entries can't be edited or removed, by anyone, including the owner. That immutability is what makes it evidence rather than notes. See Data privacy and retention.
Common questions
Does the log capture reads or only changes?
It records actions and changes — the things that alter state or move money. It isn't a keystroke recorder.
How far back does it go?
To the beginning of your workspace. Retention purges skip the audit log entirely.
Can I export it?
Use the date and entity filters to scope what you need on screen.