Audit Log
A record of who did what on your account, and when
Overview
The Audit Log records the meaningful actions taken on your account — by you and by everyone on your team. Each entry shows who did it, what they did, when, from which IP address, and on which website.
It answers the questions that come up when several people share one account: who changed that setting, who removed that team member, who exported the leads, who read the customer conversations.
Who Can See It
Only the account owner. Team members cannot open the Audit Log or see their own entries in it — it is the owner's record of what happens across their team.
What Gets Recorded
Entries fall into six categories, so you can narrow the log down to the kind of activity you are looking for.
- Sign-ins and sign-outs
- Failed sign-in attempts
- Password changes
- API key regenerated
- Single sign-on providers added, changed or removed
- Client portal links created or revoked
- Widget settings changed
- AI instructions saved or restored
- Custom tools changed
- Retention Policy changed
- Zero Retention Mode changed
- Websites added or deleted
- Content added
- Content deleted
- Website crawls started
- Team members invited
- Team members removed
- Permissions changed
- Customer conversations viewed
- Conversations deleted
- Leads exported
- The audit log itself exported
- Plan changed
- Subscription cancelled
- Account deleted
Reading Conversations
Opening the chat logs is recorded as well, so you can see when someone on your team was reading customer conversations. Because browsing generates a lot of activity, this is grouped into one entry per person per website for each hour they were reading, rather than one entry per conversation opened.
Filtering the Log
The filters above the table narrow the log down:
- Category - show only authentication, settings, knowledge base, team, data or billing activity
- Person - show only what one member of your team did
- Website - show only actions that applied to a particular site
- Date range - limit the log to a period you care about
- Search - match against the description of each action
Exporting
Export gives you the filtered results as a CSV file, which is usually what a compliance or security team asks for. Set your filters first — the export matches exactly what you are looking at.
The export itself is recorded in the log, so it is always clear who took a copy and when.
The Record Cannot Be Changed
Entries can only ever be added. Nobody can edit or delete them — not your team, not you, not our support staff. That is deliberate: an audit log that can be edited provides no assurance.
What is never recorded: the Audit Log stores actions, not content. It never contains the text of your visitors' messages or your chatbot's replies.
How Long Entries Are Kept
Entries are kept for 12 months and are then removed automatically. This is long enough for the audit cycles that usually ask for them, and it means personal data such as a former colleague's email address does not sit in the log indefinitely.
If your organisation is required to keep records for longer, contact us at [email protected] and we can set a longer window on your account.
Deciding How Long Conversations Are Kept
The Audit Log tracks what people do with your data. If you also want control over how long that data exists in the first place, these two settings cover it.
Retention Policy Set how many days conversations are kept before they are deleted Zero Retention Mode Answer questions without storing what visitors sayNote: The Audit Log is available on the Enterprise plan. Recording starts from the moment the plan is active — it cannot show activity from before that.