Account & Security
Audit log
A tamper-evident record of who did what in your organization.
Every meaningful change in your organization is recorded in the audit log, found in Settings.
What's recorded
The log captures sensitive and configuration-changing actions — for example renaming the organization, creating or revoking API keys, saving or removing an integration key, making governance allow/block decisions, and endpoint lifecycle actions. Each entry shows the action and when it happened; the most recent entries are shown first.
Sensitive values are never written to the log. When you save a VirusTotal key, for example, the entry records the provider, the masked key tail, and the validation status — never the key itself.
Integrity
Beyond the per-organization log in Settings, governance includes an audit integrity view. The audit trail is designed to be tamper-evident, so you can trust that the record reflects what actually happened.
Using the log
- Investigate change. If a policy or decision changed unexpectedly, the log shows the action and timing.
- Review access management. Track key creation/revocation and configuration changes over time.