Audit log

Who signed in, who changed permissions, who handed out keys and who exported data, with CSV export.

The audit log answers one specific question: who did what, and when, in everything that touches workspace security. It isn’t the change history of your tasks — that lives on each issue.

It’s in Settings → Audit, and admins read it.

What’s recorded

Family Examples
Identity & session login, failed login, two-step code verified or failed, password change, password reset, email verification, passkeys added and removed, 2FA enabled and disabled, devices forgotten
Members & permissions invitation sent, accepted, declined or revoked, role change, removal, project shared
Data & keys API keys created and revoked, data exports, reading and exporting the log itself, account deletion requested and purged
Billing checkout started, portal opened, subscription created, changed and cancelled, modules subscribed and dropped

Each event stores the date, the action, who did it (with the email as it was known at the time, so the log stays readable even if that account is later deleted), on what, and the IP.

Nothing sensitive is ever stored: no passwords, no tokens, no API key secret, no export contents. References, not contents.

Reading and exporting

  • Filters by action and date range, with progressive loading.
  • Export CSV takes what matches your filter, up to 5,000 events per download; if there are more, the app tells you to narrow the dates.
  • Reading and exporting are themselves recorded.

Retention

Events are kept for one year and then retired in batches automatically. The retirement is logged too.

Who can see it

Events are always written, on every plan: that’s instance security, not a paid feature. What depends on the plan is reading them, which comes with any paid plan — Pro, Team or Enterprise — but not with Free. See Billing & plans.

Related: Account security · Members & roles · Workspace settings.