Audit Log
The audit log records administrative changes in your organization: what was done, who did it, and when. It is available on the Enterprise plan.
Use it to answer questions like who removed a member, or when a project’s data retention was last changed.
Viewing the log
Section titled “Viewing the log”Organization Admins and Owners open the Audit Log tab from the organization header. Entries are listed newest first and paged.
Each entry shows:
- When — the time the action happened
- Action — a stable identifier for what was done, such as
project.visibility_changedororganization.member_removed - Actor — the user who performed the action
- Project — the affected project, for project-scoped actions
- IP — the network address the request came from
Expand a row to see action-specific details, such as the before and after values of a changed setting and the target it applied to.
What gets recorded
Section titled “What gets recorded”The log captures management actions taken through the dashboard and the API, grouped by the entity they affect.
Organization
- Membership changes — access granted or changed, members removed
- Ownership transfer, slug and billing-email changes, and organization deletion
Projects
- Creation and deletion
- Settings changes — visibility, data retention, acceptable flakiness, timezone, GitHub checks, and Slack webhook
- Upload token rotation, badge generation and removal
- Test-run deletion
Billing
- Plan changes, scheduled cancellations, and reactivations
This is a representative selection, not the complete set.
What is not recorded
Section titled “What is not recorded”- Secrets. Token values, GitHub credentials, and webhook URLs are never written to the log. The log records that a secret changed, not the secret itself.
- Test uploads. Report uploads from CI are not audit events. The log tracks management actions, not data ingestion.
- Read activity. Viewing analytics and browsing runs are not recorded.
Retention
Section titled “Retention”Audit entries are kept for one year, then removed.