Audit logs: track who did what
A timestamped record of the important actions in your account — who did what, when, from where, and through which surface (Web, API, or Copilot). Built for security reviews and SOC 2 evidence.
The audit log is a running, timestamped record of the important actions taken in your account — sign-ins, automations started, samples approved, billing changes, and more. It answers who did what, when, from where, and how — the trail you need for a security review, a SOC 2 audit, or simply working out what a teammate changed.
Where to find it
Open it from the Audit logs row on your Account page (Dashboard → Account → View audit logs), or from the ⋯ menu on any teammate's row under Dashboard → Users, which opens the log pre-filtered to that person. It's visible to the account owner and Admin sub-accounts — the same people who can manage your team. Regular Users don’t see it.
What each row tells you
Each row is a single action, newest first. The columns:
- Time — when it happened, shown in your local timezone.
- Account email — who did it. For a Cruva support or agency-manager session, this shows their email, not yours.
- Account type — a colored badge: Owner, Admin, User, External (a collaborator you granted access), Manager, Cruva staff, or System.
- Platform — where the action came through: Web (the dashboard), API (your REST key), or LLM (Copilot, or an MCP client like Claude).
- Action — a plain-English label such as “Started automation” or “Approved sample requests.” Hover to see the raw action code.
- Target — what was acted on, by name (the automation, list, or sample request).
- IP — the originating IP address with a country flag; hover for the city and region.
- Details — the route, how it happened (e.g. “via AI · create_group” or “via API key”), and any extra context for that action.
Filtering and searching
Narrow the log with the controls at the top: by user, by action type, by platform (Web / API / LLM), and by date range. The search box matches across the action, target, route, and email. Opening the log from a teammate’s row deep-links straight to their activity.
What gets recorded
Security and account events, plus the important actions across the product:
- Sign-in activity — successful logins, failed login attempts (with the reason), and two-factor enable, disable, and failures.
- Staff & manager sessions — when Cruva support observes your account, or an agency manager signs in, it’s logged under their email, not yours.
- Product actions — automations, email campaigns, groups, sample requests and rules, creator briefs, community campaigns, and billing changes.
- API & Copilot actions — anything done through the REST API or through Copilot / MCP appears with the API or LLM badge.
External collaborators you’ve granted access to appear here too, tagged External, so you can see exactly what a partner did inside your shop.
How long entries are kept
Audit entries are retained for 90 days. If you need a longer record for a compliance window, export what you need before it ages out.
Audit logs are read-only — there’s no way to edit or delete an entry from the dashboard, which is what makes them trustworthy as evidence.
Was this article helpful?
Related articles
- White-label manager emailConfigure a white-label manager email so brands install Cruva via your own email, not a Cruva-generated one.
- Custom client invoicingBill agency clients directly for the Cruva seats they use.
- Move shops between accountsHand off a shop to another Cruva account without losing data.
- Add team members and manage sub-usersInvite team members, choose Admin vs User roles, resend expired invites, remove a user, and log out other devices.
- Agencies: multiple shops, transfers, and partner accountsManage multiple brand shops under one account, transfer a shop and its billing between agency and brand, and understand which account types Cruva connects.
- Account Settings