# Audit and history

**You'll need:** an administrative role. Four screens, answering four different
questions.

## History

**Administration → History.** Every change to a record, with the **before and after**.

Each entry carries the table, the record, the operation (insert, update, delete), who
made it, when, and the changeset itself. Select an entry to see the record as it stood
after that change, with who made it and when.

Use this screen for *"who changed the refund policy, and what did it say before"*. The
answer is exact, because the previous value is stored rather than inferred.

You can search by table, record, user or timestamp.

Many screens also have their own history view (an agent, a knowledge record) showing
the same data scoped to that one item, which is usually easier than filtering the global
list.

## Access Log

**Administration → Access Log.** Every request: who, when, what method and URL, and the
parameters.

Use this screen for *"did anything read that"* and for tracing an integration's
behavior. It records requests rather than changes, so it includes reads that changed
nothing.

Searchable by user, method, URL and time.

## Security Activity

**Administration → Security Activity.** Sign-ins, password changes and blocked attempts
across the workspace, as reported by the identity provider.

Use this screen for *"who signed in from where"* and for a sign-in someone does not
recognize. Searchable by user, event type, IP address and country.

## Share Links

**Administration → Share Links.** Every public link in the workspace, with who created
it, what it exposes, how often it has been viewed and downloaded, and when it expires.

Review this screen on a schedule. Sort by expiry and check the links that never expire.
See [share links](/guide/media/share-links).

## Which screen to open

| The question | The screen |
|---|---|
| Who changed this, and what was it before? | History |
| Who has been accessing this? | Access Log |
| Who signed in, and from where? | Security Activity |
| What is publicly reachable right now? | Share Links |
| Who gave someone this access? | History, filtered to users and roles |
| Where did the credits go? | [Usage Details](/guide/admin/usage-and-credits) |

## Retention

History is kept. The access log is kept for a month, and older entries age out: it is an
operational log rather than an archive, so if compliance requires a record beyond that
window, export it while it is still available.

<Callout type="note">
	The same history and access log are available through the API, so compliance
	reporting can be pulled on a schedule rather than assembled by hand. See the
	[developer documentation](/developers).
</Callout>
