The workspace audit log records who did what, when, from where: settings changes, data operations, permission changes, exports, API activity, and agent configuration. Searchable, exportable, SIEM-streamable.
What's captured
Every settings and configuration change (before/after values), user and role events, data exports (who exported what), suppression and deletion operations, integration changes, API key usage, and agent guardrail edits.
Searching
Settings → Audit Log: filter by actor, event type, object, date, and IP. "Who changed the ICP threshold in May" is a ten-second query.
Retention and export
Retention by plan (1 year standard, 7 years Enterprise). Export to CSV on demand, or stream continuously to your SIEM (Splunk, Datadog, generic syslog/HTTP) from the same page.
Compliance role
The log satisfies SOC 2 and ISO change-management evidence requirements — auditors get filtered exports rather than screenshots. Pair with integration audit and enrichment audit for full data-lineage coverage.