Audit log
Who signed in, who changed permissions, who handed out keys and who exported data, with CSV export.
The audit log answers one specific question: who did what, and when, in everything that touches workspace security. It isn’t the change history of your tasks — that lives on each issue.
It’s in Settings → Audit, and admins read it.
What’s recorded
| Family | Examples |
|---|---|
| Identity & session | login, failed login, two-step code verified or failed, password change, password reset, email verification, passkeys added and removed, 2FA enabled and disabled, devices forgotten |
| Members & permissions | invitation sent, accepted, declined or revoked, role change, removal, project shared |
| Data & keys | API keys created and revoked, data exports, reading and exporting the log itself, account deletion requested and purged |
| Billing | checkout started, portal opened, subscription created, changed and cancelled, modules subscribed and dropped |
Each event stores the date, the action, who did it (with the email as it was known at the time, so the log stays readable even if that account is later deleted), on what, and the IP.
Nothing sensitive is ever stored: no passwords, no tokens, no API key secret, no export contents. References, not contents.
Reading and exporting
- Filters by action and date range, with progressive loading.
- Export CSV takes what matches your filter, up to 5,000 events per download; if there are more, the app tells you to narrow the dates.
- Reading and exporting are themselves recorded.
Retention
Events are kept for one year and then retired in batches automatically. The retirement is logged too.
Who can see it
Events are always written, on every plan: that’s instance security, not a paid feature. What depends on the plan is reading them, which comes with any paid plan — Pro, Team or Enterprise — but not with Free. See Billing & plans.
Related: Account security · Members & roles · Workspace settings.