Guides

Review audit logs

Review access, session, assignment, and closure records in their event context.

Page type: GuideAudit logsStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

Audit logs show who acted on which resource and session, and when. Read the start, change, and closure context together instead of relying on one row.

Prerequisites

A role that can view workspace audit records is required.

Review flow

  1. Select the workspace and time range.
  2. Filter by member, resource, session, or action type.
  3. Order access request, approval, session start, change, and closure events.
  4. Compare the sequence with the expected closure or revocation record.
  5. Add the relevant record context to a support ticket when needed.

Do not alter records or copy sensitive values. See revocation and evidence for the evidence and closure model.

Result

The filtered event sequence shows the access decision and closure state in the same workspace context.