> ## Documentation Index
> Fetch the complete documentation index at: https://docs.begin.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit log

> Search workspace activity and inspect who changed what and when.

<img src="https://mintcdn.com/beginltd/zeGlKdCOG-PEugD7/images/cover/settings-audit-log-light.png?fit=max&auto=format&n=zeGlKdCOG-PEugD7&q=85&s=cb7597cf52542b5225e7ad3bea915d59" alt="An audit event card showing a workspace settings change by Anna Kask" className="block dark:hidden" noZoom width="1152" height="616" data-path="images/cover/settings-audit-log-light.png" />

<img src="https://mintcdn.com/beginltd/zeGlKdCOG-PEugD7/images/cover/settings-audit-log-dark.png?fit=max&auto=format&n=zeGlKdCOG-PEugD7&q=85&s=ef51a4ee615663b7d39dc29ab3bbcd26" alt="An audit event card showing a workspace settings change by Anna Kask" className="hidden dark:block" noZoom width="1152" height="616" data-path="images/cover/settings-audit-log-dark.png" />

Use **Settings → Audit log** to investigate who changed a workspace record and when. Check the workspace switcher first so you search the right organisation.

<Info>
  You need **View audit log** on your role. The audit log is a Pro feature: on Free, Standard or a
  trial the page shows an upgrade message.
</Info>

<img src="https://mintcdn.com/beginltd/O3eNHOhbC75NvE_t/images/articles/settings/settings-audit-log-screen-light.png?fit=max&auto=format&n=O3eNHOhbC75NvE_t&q=85&s=b56fa7c7b70f6539e6f7322c2fa6b3c9" alt="The real Audit log with search, filters, and recent workspace events" className="block dark:hidden" width="2944" height="1840" data-path="images/articles/settings/settings-audit-log-screen-light.png" />

<img src="https://mintcdn.com/beginltd/O3eNHOhbC75NvE_t/images/articles/settings/settings-audit-log-screen-dark.png?fit=max&auto=format&n=O3eNHOhbC75NvE_t&q=85&s=a8bba81f62341fcda37b81f11d382194" alt="The real Audit log with search, filters, and recent workspace events" className="hidden dark:block" width="2944" height="1840" data-path="images/articles/settings/settings-audit-log-screen-dark.png" />

## Find an event

<Steps>
  <Step title="Narrow the period">
    Open the filter control and choose the date range around the change you are investigating.
  </Step>

  <Step title="Find the person or record">
    Search by action or actor. Add an actor or resource filter if you know who made the change or
    which kind of record was affected.
  </Step>

  <Step title="Refine the results">
    Filter **Origin** to separate **Person**, **AI**, **Begin support**, **System**, **System
    automation**, **Via terminal** and **MCP** activity. Add severity when you need a particular
    event level.
  </Step>
</Steps>

The current search and filters are saved for this workspace when you leave the page.

Scroll to load older events. Clear the search or remove filter chips when the result is too narrow. Events are kept for the life of the workspace; there is no age limit, and upgrading shows events recorded before the upgrade.

For one person, the **History** tab on their profile shows the same events narrowed to them.

## Read the details

Select an event to see its actor, time, origin, and recorded changes. Depending on the event, the detail can also include an IP address or affected resource.

Changes made during Begin support access are recorded under the support person's name. Use the actor and recorded details to distinguish their work from your own team's activity. Where a resource link is available, open it to move from the event to the relevant record.

<Note>
  A missing change in the detail does not prove that nothing changed. An event can only show the
  information recorded by that action. The Audit log page does not export events.
</Note>

**Context for an assistant helping with Audit log.** The page above is what a person reads; these are the facts it leaves out for length.

* **Who can:** a role needs **View audit log**. The capability is included only in the Pro plan. The default employee and manager roles do not include audit-log access.
* **Needs:** search and filter state is tied to the current workspace and restored from the route. Filters include severity, resource, origin, actor, from date, and until date.
* **Limits:** event detail depends on what the originating action recorded. Older events may contain less metadata. The table loads older results as the person scrolls. Entries are never deleted for age.
* **Not supported:** the current Audit log page does not export events. It cannot reconstruct a value that was never captured in event metadata.
* **Often confused with:** person history, which narrows events to one member. Audit log searches activity across the workspace.

## Next

<Columns cols={2}>
  <Card title="Roles and permissions" icon="shield" href="/for-managers/people/roles-permissions">
    Grant **View audit log** without broadening unrelated access.
  </Card>

  <Card title="Support access" icon="headset" href="/for-managers/workspace/support-access">
    Review or revoke temporary support access.
  </Card>
</Columns>

## Still need help?

<Columns cols={2}>
  <Card title="Contact support" icon="envelope" href="mailto:support@heybegin.eu">
    Email the Begin team and we'll get back to you.
  </Card>

  <Card title="Ask Begin AI" icon="comment-dots" href="?assistant=open">
    Open the AI assistant and get instant answers based on these docs.
  </Card>
</Columns>
