---
title: Audit logs
slug: audit-logs
description: Monitor user activity across your organization or team.
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2025-02-03T13:28:13.882Z
---

:::hint{type="info"}
This feature is available on **Enterprise plans**.
:::

Audit logs allow you to monitor user activity within your organization or team. This information is particularly useful for resolving issues and troubleshooting incidents. For example, if a crucial scenario transferring data between systems unexpectedly fails, audit logs can help you identify who updated the scenario and when it happened.

Audit logs are available on the Enterprise plan only. Organization owners and admins as well as team admins can access audit logs.

Audit logs are stored for 12 months.

## Organization audit logs

Audit logs are available at both the organization and team levels. Organization audit logs give you visibility into everything that is happening in your organization, including such events as creating or updating the organization variable.

Organization Audit logs are visible only to organization owners and admins.

To open Audit logs from the Organization dashboard:

::::WorkflowBlock
:::WorkflowBlockItem
Click **Org** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **Org** **Audit Logs** tab.

Once you open the tab, you will see the audit logs for the organization you’re in. You can filter what you see to show only specific events, specific time periods, or users by setting up filters on the filter panel.

Additionally, you can select to see only events from specific teams in the audit logs.
:::

:::WorkflowBlockItem
Click the **All filters** button.
:::

:::WorkflowBlockItem
Select the teams for which you want to see the logs in the **Team** dropdown.
:::

:::WorkflowBlockItem
Click **Apply**.
:::
::::

## Team audit logs

Team audit logs are available to team admins. Organization owners and admins can see team audit logs through the audit logs in the Organization dashboard or by opening the audit logs for a specific team from the Team dashboard.

To view audit logs from the Team dashboard:

::::WorkflowBlock
:::WorkflowBlockItem
Click **Team** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **Team** **Audit Logs** tab.
:::
::::

You will see the audit logs for your team. You can filter the logs to display specific events or time periods.

## Available events

The audit logs allow you to see what was changed, who made the change, when it was made, and for which scenario.

:::hint{type="info"}
Some of the events are not visible in the team audit logs. For example, you won’t see events about organization variables, but you will see events connected to this specific team (team member added, removed, etc.).
:::

| **Event category**                    | **Available events**                                                                                                                                               | **Available for organization** | **Available for team** |
| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------ | ---------------------- |
| Scenarios                             | - Scenario created
- Scenario updated
- Scenario deleted
- Scenario activated
- Scenario deactivated
- Scenario settings updated
- Scenario restored               | Yes                            | Yes                    |
| Connections                           | * Connection created
* Connection deleted
* Connection updated
* Connection authorized/reauthorized                                                                | Yes                            | Yes                    |
| Webhooks                              | - Webhook created
- Webhook deleted
- Webhook updated
- Webhook enabled
- Webhook disabled                                                                         | Yes                            | Yes                    |
| Keys                                  | * Key created
* Key updated
* Key deleted                                                                                                                          | Yes                            | Yes                    |
| Team                                  | - Team created
- Team updated
- Team deleted
- Team role updated
- Team member removed                                                                             | Yes                            | Yes                    |
| Team variables                        | * Team variable created
* Team variable updated
* Team variable deleted                                                                                            | Yes                            | Yes                    |
| Organization variables                | - Organization variable created
- Organization variable updated
- Organization variable deleted                                                                    | Yes                            | No                     |
| Organization                          | * Organization member removed
* Organization role updated
* Organization private spaces setting updated
* Custom role deleted                                      | Yes                            | No                     |
| Data store                            | - Data store created
- Data store updated
- Data store deleted                                                                                                     | Yes                            | Yes                    |
| Data store records                    | * Data store record created
* Data store record updated
* Data store record deleted                                                                                | Yes                            | Yes                    |
| Data structure                        | - Data structure created
- Data structure updated
- Data structure deleted                                                                                         | Yes                            | Yes                    |
| Functions                             | * Function updated
* Function created
* Function deleted                                                                                                           | Yes                            | Yes                    |
| Two-factor authentication enforcement | - Organization 2FA enforcement enabled
- Organization 2FA enforcement disabled                                                                                     | Yes                            | No                     |
| Credential requests                   | * Credential created
* Credential authorized
* Credential declined
* Credential connection deleted
* Credential key deleted
* Credential reauthorization requested | Yes                            | Yes                    |
| Identity and access                   | - SSO enabled
- SSO updated
- SSO disabled&#x20;                                                                                                                   | Yes                            | No                     |
| Private spaces                        | * Private space created
* Private space updated
* Private space deleted
* Private space admin added
* Private space admin removed                                  | Yes                            | Yes                    |
| Credential usage                      | - Connection used belongs to someone else
- Requested connection used
- Key used belongs to someone else
- Requested key used                                      | Yes                            | Yes                    |

:::hint{type="info"}
Events related to data store records (like Data store record updated) only apply to actions done within the Make interface or API. They don't apply to actions done through the datastore modules.
:::

## Event details

The audit log main page provides a summary of who performed specific actions and when they occurred. For more detailed information about an event, click the **Details** button next to the entry. A pop-up window will appear, displaying additional data about the event. To copy any information, click the **Copy** button within the pop-up.
