Skip to main content
The audit log records changes to your organization: users invited and removed, roles changed, license keys created and revoked, alert rules and dashboards edited, and any support access granted.
Reading the audit log requires the Auditor, Admin or Owner role. Auditor exists specifically for this: it grants read access to the audit log and cannot change anything at all, which is exactly what a compliance reviewer should hold. See Roles and permissions.

What is recorded

Each entry carries the actor, the action, the resource type and identifier, and the time.

Support access is in your log

When aiAxonIQ support is granted time-limited access to your organization to investigate a ticket, that appears here — who, when, and for how long.It is deliberately in your audit log rather than only in an internal one. An access record you cannot read is a policy; one you can read is a control.

Filtering

Filter by action type and by resource type, both of which are enumerable — so you can see what kinds of events exist rather than guessing at strings. An individual entry can be opened for its full detail. The common questions:
  • Who revoked that key? Filter to credential actions.
  • What changed before this alert started misfiring? Filter to the rule’s resource type around the time it began.
  • Who has been added to this organization this quarter? Filter to membership.

Export

The log can be exported for a compliance review or to keep alongside your own records.
Export before you need it, not after. The audit log is not exempt from retention. If your compliance process requires records for longer than the platform keeps them, a periodic export is the mechanism — there is no archive to request later.

What is not here

The audit log records control-plane changes, not telemetry access. It does not record every dashboard someone viewed or every log search someone ran.If your requirement is “prove nobody read this data”, that is a boundary question rather than a logging one — the answer is a separate organization, because every member of an organization can read all of its telemetry. See Organizations and multi-tenancy.
Detections about your systems — authentication failures, exposed secrets, runtime threats — are security events, which is a different surface. During an investigation you usually want both.

Next

Roles and permissions

The Auditor role, and who may grant it.

Security events

Detections over your telemetry.

Organizations

Where the real access boundary is.