Skip to main content

Audit logs

Find recorded organization changes, inspect event details, export results, and check the audit chain.

3 min read

Open Settings > Governance > Logs as an Admin or Owner to investigate recorded actions in your organization. Start with the event and time you need, then inspect its actor, target, result, and available change details.

Find a change

  1. Select Audit logs and open Filter.
  2. Choose a category relevant to the action, such as member changes, security, or data.
  3. Find the event by timestamp, action, and target. Open its row to inspect the details.
  4. Check the status before interpreting the event: an attempted action marked denied or failed does not establish that the change succeeded.

The active tab and category are reflected in the URL, so you can bookmark the view. Access still depends on your organization permissions.

Read an event

FieldWhat to look for
TimestampWhen Tale recorded the action.
ActionThe operation that was attempted or completed. Some newer actions appear by their technical name.
UserThe person or system actor responsible for the action.
Resource and targetThe kind of item and the particular record affected.
CategoryThe grouping used by the filter.
StatusSuccess, failure, or denied.
Detail viewAvailable previous/new state, changed fields, metadata, and error information. Not every event has every field.

Treat the log as evidence of the events it records. It is not a complete copy of every conversation, provider response, or external service's activity.

Choose the right tab

Audit logs contains individual events; the table loads more as you scroll, and its footer states how many events are loaded so far, so a count is never the whole history until the footer says so. Sign-in blocks helps investigate authentication lockouts. Activity logs summarizes activity and outcomes over a period: the period chosen in its Filter (7, 30, or 90 days) is named above the totals, and every number on the tab covers that period only. Error logs focuses on failures; its category filter helps narrow the investigation.

When a member cannot sign in, begin with the sign-in blocks and the account security guidance. When a configuration changed unexpectedly, use the audit event and its detail view.

Export results

Set the category filter, then open Export and choose CSV or JSON. CSV provides flat columns for spreadsheets, including UTC timestamps, actor identifiers, resource identifiers, status, and errors. JSON preserves the fuller event objects, including available change payloads and integrity hashes.

Exports honor the category filter and contain at most 10,000 rows, newest first. They are generated on the server and downloaded through a temporary link. A filtered or capped export is a selection of evidence; it is not necessarily the entire audit history or a complete hash chain.

Retention and integrity

Use Verify now in Chain integrity to check the stored audit chain. The panel shows its status and the latest automated check. If a check reports a break, preserve the reported details and investigate with the deployment operator before relying on that segment of history.

A successful check covers the retained records it examined; it does not establish an independently signed origin for the history. The operator integrity guide explains the checks and their limits.

Hash chaining helps detect changes to stored records; it does not prove that every possible action was logged. Audit retention is configurable under Policies and limits. Check the active policy and deployment bounds instead of assuming a fixed retention period. Recoverable audit records can appear in Trash; permanent cleanup limits the history available here.

Scheduled retention cleanup records each of its runs here as system events in the Data category: when the run started, how many records each category deleted, and whether the run completed or failed.

© 2026 Tale by Ruler GmbH — ISO 27001 & SOC 2 certified.

Tale is MIT licensed — free to use, modify, and distribute.