# 29.Audit logs

# Audit logs

| Item | Details |

|—|—|

| Who it is for | Administrators |

| Menu location | **Settings → Audit logs** |

| Plan dependency | Requires Audit Logs |

A security and compliance stream of “who did what, when” inside the workspace — for accountability and diagnosing mistakes. It is not the conversation transcript.

## 1. Events you may see (examples)

Varies by version; commonly includes:

– Sign-in related events, agent invites and role changes

– Create / update / delete of inboxes, automation, macros, labels

– Help Centre portal / article admin actions

– Captain document and FAQ changes

– SAML / security settings

– Create, update, delete on other admin objects

Each row usually has: actor, time, object type and ID, action summary.

Day-to-day agent replies to customers **usually do not** appear line-by-line here (those are conversation messages). Audit focuses on configuration and permissions.

## 2. How to use

1. Filter by time, actor and type.

2. When a bad config appears, match it to the actor at that timestamp.

3. Export if the button is available, and retain copies per your compliance timeline.

Logs themselves follow retention policy — do not treat them as a permanent archive. Record important changes in your own change tickets too.

## 3. Frequently asked questions

**No menu?** Plan does not include it.

**Cannot find a label change?** That event type may not be covered, or it happened before audit was enabled.

**Actor shows as system?** Automation, a platform job or an API token. Cross-check webhooks / the automation list.

## Related articles

– [Account settings and security](.27-account-settings-and-security

– [Agents](./13-agents)