Audit logs: track who did what

A timestamped record of the important actions in your account — who did what, when, from where, and through which surface (Web, API, or Copilot). Built for security reviews and SOC 2 evidence.

The audit log is a running, timestamped record of the important actions taken in your account — sign-ins, automations started, samples approved, billing changes, and more. It answers who did what, when, from where, and how — the trail you need for a security review, a SOC 2 audit, or simply working out what a teammate changed.

Where to find it

Open it from the Audit logs row on your Account page (Dashboard → Account → View audit logs), or from the menu on any teammate's row under Dashboard → Users, which opens the log pre-filtered to that person. It's visible to the account owner and Admin sub-accounts — the same people who can manage your team. Regular Users don’t see it.

What each row tells you

Each row is a single action, newest first. The columns:

  • Time — when it happened, shown in your local timezone.
  • Account email — who did it. For a Cruva support or agency-manager session, this shows their email, not yours.
  • Account type — a colored badge: Owner, Admin, User, External (a collaborator you granted access), Manager, Cruva staff, or System.
  • Platform — where the action came through: Web (the dashboard), API (your REST key), or LLM (Copilot, or an MCP client like Claude).
  • Action — a plain-English label such as “Started automation” or “Approved sample requests.” Hover to see the raw action code.
  • Target — what was acted on, by name (the automation, list, or sample request).
  • IP — the originating IP address with a country flag; hover for the city and region.
  • Details — the route, how it happened (e.g. “via AI · create_group” or “via API key”), and any extra context for that action.

Filtering and searching

Narrow the log with the controls at the top: by user, by action type, by platform (Web / API / LLM), and by date range. The search box matches across the action, target, route, and email. Opening the log from a teammate’s row deep-links straight to their activity.

What gets recorded

Security and account events, plus the important actions across the product:

  • Sign-in activity — successful logins, failed login attempts (with the reason), and two-factor enable, disable, and failures.
  • Staff & manager sessions — when Cruva support observes your account, or an agency manager signs in, it’s logged under their email, not yours.
  • Product actions — automations, email campaigns, groups, sample requests and rules, creator briefs, community campaigns, and billing changes.
  • API & Copilot actions — anything done through the REST API or through Copilot / MCP appears with the API or LLM badge.

External collaborators you’ve granted access to appear here too, tagged External, so you can see exactly what a partner did inside your shop.

How long entries are kept

Audit entries are retained for 90 days. If you need a longer record for a compliance window, export what you need before it ages out.

Audit logs are read-only — there’s no way to edit or delete an entry from the dashboard, which is what makes them trustworthy as evidence.

Was this article helpful?

Related articles