# Audit logs
| Item | Details |
|—|—|
| Who it is for | Administrators |
| Menu location | **Settings → Audit logs** |
| Plan dependency | Requires Audit Logs |
A security and compliance stream of “who did what, when” inside the workspace — for accountability and diagnosing mistakes. It is not the conversation transcript.
—
## 1. Events you may see (examples)
Varies by version; commonly includes:
– Sign-in related events, agent invites and role changes
– Create / update / delete of inboxes, automation, macros, labels
– Help Centre portal / article admin actions
– Captain document and FAQ changes
– SAML / security settings
– Create, update, delete on other admin objects
Each row usually has: actor, time, object type and ID, action summary.
Day-to-day agent replies to customers **usually do not** appear line-by-line here (those are conversation messages). Audit focuses on configuration and permissions.
—
## 2. How to use
1. Filter by time, actor and type.
2. When a bad config appears, match it to the actor at that timestamp.
3. Export if the button is available, and retain copies per your compliance timeline.
Logs themselves follow retention policy — do not treat them as a permanent archive. Record important changes in your own change tickets too.
—
## 3. Frequently asked questions
**No menu?** Plan does not include it.
**Cannot find a label change?** That event type may not be covered, or it happened before audit was enabled.
**Actor shows as system?** Automation, a platform job or an API token. Cross-check webhooks / the automation list.
—
## Related articles
– [Account settings and security](.27-account-settings-and-security
– [Agents](./13-agents)