Audit log
Every change made through the portal, and every job created, is written to the audit log in the same database transaction as the change itself. Each entry records:
- who (user, or automation such as release publishing);
- what (action, resource type and ID);
- when;
- where from (IP address and user agent);
- before and after values, with secrets redacted.
Tenant admins read their tenant's log under Audit log and can search it. Global admins have an installation-wide log under Admin → Audit log.
The log is append-only: the application's database role cannot change or delete entries. Old entries are removed only by the retention job (365 days by default, per tenant 30–3650 days in Tenant settings).