Audit and history
You'll need: an administrative role. Four screens, answering four different questions.
History
Administration → History. Every change to a record, with the before and after.
Each entry carries the table, the record, the operation (insert, update, delete), who made it, when, and the changeset itself. Select an entry to see the record as it stood after that change, with who made it and when.
Use this screen for "who changed the refund policy, and what did it say before". The answer is exact, because the previous value is stored rather than inferred.
You can search by table, record, user or timestamp.
Many screens also have their own history view (an agent, a knowledge record) showing the same data scoped to that one item, which is usually easier than filtering the global list.
Access Log
Administration → Access Log. Every request: who, when, what method and URL, and the parameters.
Use this screen for "did anything read that" and for tracing an integration's behavior. It records requests rather than changes, so it includes reads that changed nothing.
Searchable by user, method, URL and time.
Security Activity
Administration → Security Activity. Sign-ins, password changes and blocked attempts across the workspace, as reported by the identity provider.
Use this screen for "who signed in from where" and for a sign-in someone does not recognize. Searchable by user, event type, IP address and country.
Share Links
Administration → Share Links. Every public link in the workspace, with who created it, what it exposes, how often it has been viewed and downloaded, and when it expires.
Review this screen on a schedule. Sort by expiry and check the links that never expire. See share links.
Which screen to open
| The question | The screen |
|---|---|
| Who changed this, and what was it before? | History |
| Who has been accessing this? | Access Log |
| Who signed in, and from where? | Security Activity |
| What is publicly reachable right now? | Share Links |
| Who gave someone this access? | History, filtered to users and roles |
| Where did the credits go? | Usage Details |
Retention
History is kept. The access log is kept for a month, and older entries age out: it is an operational log rather than an archive, so if compliance requires a record beyond that window, export it while it is still available.
The same history and access log are available through the API, so compliance reporting can be pulled on a schedule rather than assembled by hand. See the developer documentation.
