turgo keeps a tamper-evident audit trail of user and system actions — logins, permission changes, data edits, API calls, and agent actions. Retention is 90 days on Build, 1 year on Growth, and 7 years on Enterprise, with export to CSV/JSON.
What's logged
Authentication events (login, SSO, failed attempts), administrative changes (roles, users, integrations, API keys), data changes with before/after values, API calls attributed to their key, and agent actions from the timeline. Each entry records who, what, when, and source.
Where to find it
Settings → Audit Log (org-wide administrative events) and Data → Audit Log (record-level Golden DB changes — see Auditing Golden DB updates). Filter by user, object, source, action type, or date range to answer a specific question quickly.
Retention by plan
90 days on Build, 1 year on Growth, 7 years on Enterprise. Beyond retention, logs are archived to cold storage and remain recoverable via support ticket for one additional year. Enterprise customers with longer statutory requirements can discuss extended retention.
Export for auditors
Filter to the scope an auditor needs and click Export for CSV or JSON. This is the standard artifact for SOC 2, ISO, or internal access reviews. For continuous export, stream audit events to your SIEM via the API or webhooks.