Audit Trail

Audit Trail is the durable, append-only record of sensitive changes in your organization — not the same as application logs.

Who can view

Open Audit Trail in the top nav when you have audit.view (or are Organization Admin). Admins get it automatically; grant the key on officer roles (Board, Treasurer, …) when those hats should review history.

There is no product update or delete API for audit rows — events are written once and kept for review.

What is recorded

Expect audit events for mutations that affect:

  • Identity / security — sign-in success/failure/lockout, password set/reset, invite accept/create/revoke
  • Org access — membership create/update/deactivate, Admin flag, role grants, membership types, organization create
  • Billing / money — estimate→invoice, invoice send/void/pay/refund, offline payment, provider webhook status changes
  • Documents — upload, delete/purge, folder ACL, retention / legal hold
  • Terms — Terms accept / re-accept

Each event includes actor, action, organization, entity type/id, and small structured detail — never passwords or file bytes.

How to use it

  1. Confirm your role has audit.view (or use an Admin account).
  2. Open Audit Trail from the primary nav.
  3. Review recent events when investigating access changes, billing disputes, or document ACL questions.

See also