Review the audit log
The audit log is the immutable record of platform activity and configuration change: who did what, when, and with what result. Use it to prove a change happened and to answer an auditor without reconstructing the story from screenshots.
It is distinct from the governance decisions log, which records what policies did rather than what people changed. Learn more: Review policy decisions.
Find an entry
-
Go to the Audit Log section under Runtime in the navigation panel.
-
Narrow the list with the filters. They apply as you set them, so there is nothing to submit.
Filter
What it narrows by
Event Type
The canonical event the system recorded.
Actor, Actor Type
Who performed the action, and whether it was a user, a service principal, the system, or a worker.
Result
How the action resolved.
Origin
The surface the action came from.
From, To
The time range, to the minute.
-
Filter by agent in the search box at the end of the filters. Enter part of the agent's name or its ID, then press Enter or leave the box.
-
Sort the list by clicking a column header.
As a result, the list narrows to the entries you need. Each row shows the timestamp in your local time zone, the actor and actor type, the event type, a plain-language summary, the result, the agent, and the origin.
To take the filtered list out of the platform, click Export CSV.
Inspect an entry
Click the View details icon on a row to open Audit Entry Details, which holds the summary and the payload the platform recorded for that event. The row's Actions menu carries what else you can do with the entry.
Verify a change you just made
- Perform the change, for example, creating an environment or editing an agent.
- Go to the Audit Log section.
- Set the From and To filters to today.
- Find the entry, for example,
environment.createdfor a new environment, "Agent updated" for an edit to an agent draft, or "Outbound destination policy changed" for a saved destination policy of a telephony integration.
As a result, you have evidence the change happened, by whom, and when — which is what makes a rollback defensible and an audit answerable.
The log records changes to the platform, not every action inside an agent. Edits to an agent draft appear as an "Agent updated" entry that names the user. The entry records that the draft changed, not the changed values, and appears at most once every five minutes per agent and user. To see which version of an agent runs where, use the agent's version history and the Deployments section. Learn more: Publish, deploy, and promote an agent version.