Skip to main content

Audit logs

Written by Product Management

This article is auto-synced from its in-app version in Tai.

Audit logs record every security-relevant action in your account — logins, user changes, agent operations, and more — with a timestamp, actor, and resource.

When you'd use this

Use Audit logs to investigate what happened and who did it. For example: check which user deleted a connector yesterday, or confirm that a new team member's invitation was accepted.

Steps

Browse audit logs

  1. In the Workbench sidebar, click Audit logs (under the Monitoring section).

  2. The table shows log entries newest-first — action, actor, company, resource type, resource ID, timestamp, and IP address.

  3. Click the Timestamp column header to toggle between newest-first and oldest-first order.

Search and filter

  1. Type in the search bar to find entries by actor email, resource ID, or other text fields.

  2. Use the Action filter chip to narrow to a specific action type — for example LOGIN_SUCCESS, USER_INVITED, or AGENT_DELETED.

  3. Use the Resource type filter chip to show only entries for a particular kind of resource — for example user, agent, or connector.

  4. Combine search and filters freely. The active filter count badge shows how many filters are applied.

  5. Click Clear all to reset search and filters at once.

Load more entries

  1. Scroll to the bottom of the table.

  2. Click Load more to fetch the next page of results.

Tips and limits

  • Audit logs are append-only and cannot be deleted or edited.

  • The search matches on actor email, resource ID, and related text fields — it does not search the full action name (use the Action filter chip for that).

  • Entries are retained according to your account's data-retention policy. Contact support if you need older records.

  • The IP address column shows the client address at the time of the action. It may be blank for system-generated events.

Related

Did this answer your question?