> ## Documentation Index
> Fetch the complete documentation index at: https://docs.famulor.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit log

> See who changed what across your workspace, and when

The audit log is your workspace's own change record: what was changed, who changed it, and when. It is the page to open when a compliance review asks how a setting came to be the way it is, or when something in the workspace stopped behaving as expected.

Find it under **Settings → Data → Audit Log**. Only workspace owners and admins see it, and it requires a plan that includes **Audit Log** — on a plan without it, the panel shows an upgrade link to **Settings → Plan** instead of entries.

## What it records

Entries are written as changes happen, across assistants and their tools, automations and campaigns, audience and knowledge-base content, telephony (numbers, SIP trunks, carrier connections, caller IDs), channels and email addresses, workspace settings such as [retention](/settings/data-retention) and [dark windows](/settings/dark-windows), and security actions — API keys created or revoked, members invited or removed, roles changed.

Each row names the person who acted, or **API / System** when the change came from a key or an automatic process rather than someone signed in, together with the action, the resource it touched, and the time. Newest entries sit on top. Use the page controls at the bottom to move between pages — each page loads a fresh set of entries.

## Search and sort

Type in the search box to keep only the entries matching an action, a resource, or the name or email of whoever made the change. Select the **Action** or **Time** column header to sort by it, and select it again to reverse the direction.

## Reading an entry

Select a row to expand it. A change to existing settings lists each field that changed with its before and after value side by side; other entries show whatever detail was recorded with them.

Some entries carry an impersonation marker. It means the action was taken while a support session was acting on the workspace's behalf, rather than by a workspace member signed in directly.

## See also

[Trust Center](/support/trust-center) and [Roles and team management](/settings/workspaces#roles-and-team-management).
