# Audit log

> See who changed what in your intoCHAT account: what the audit log records and never records, who can see it, how long each plan keeps it, filters and CSV export.

The audit log shows who changed what in your account, and when: agents created, changed or deleted, knowledge, actions, webhooks and integrations, API keys, team changes, exports and contact imports. It covers everyone who works in the account, you included. Open it under **Settings**, **Audit log**.

It's included on Pro and Enterprise. On Free and Starter the page says it's included from Pro.

## Who can see it

- The account owner and admins, on all agents. On Enterprise, also a [custom role](/en/docs/team#custom-roles) with **Manage** on **Team**.
- Not editors or viewers, and not members [limited to selected agents](/en/docs/team#access-to-selected-agents): the log covers the whole account.

## What it records

Each event has the time, who did it, what they did and to what, the agent it concerns, and the network they were on.

| Group | Events |
| --- | --- |
| Agents | Agent created, duplicated or deleted; agent settings changed (with which settings); an earlier version of the settings restored |
| Knowledge | Source added or deleted |
| Actions, procedures and forms | Action, procedure or form created, updated or deleted |
| Integrations and webhooks | Webhook created, updated or deleted, its signing secret rotated; an integration connected or disconnected (booking, store orders, helpdesk, Slack, Notion, Shopify) |
| Team and roles | Someone invited, removed or leaving; an invitation accepted; a role changed (from and to); which agents someone can use changed; a custom role created, updated or deleted |
| API keys | API key created or revoked |
| Billing | Plan changed |
| Security and sign-in | Two-factor sign-in turned on or off; a new identity verification secret generated |
| Exports and imports | An export downloaded (leads, contacts, form submissions, knowledge sources or the audit log's own CSV) and a contacts CSV import |

Events from the billing system, such as a plan change after a payment, show **System** as who did it.

## What it never records

- Secrets: passwords, API keys, webhook signing secrets, tokens, store or helpdesk credentials. Anything that names or looks like a secret is dropped before an event is saved.
- Message content, conversation transcripts, and your visitors' or customers' details.
- What people only looked at. Reading is not recorded; only changes and downloads are.

The name of the thing changed and the person's email address are saved as they were at the time, so the log still reads the same after someone leaves or an agent is deleted.

## IP addresses

Only the first part of the address is kept: the /24 network for IPv4 (for example `203.0.113.0/24`) and the /48 network for IPv6. That's enough to tell "the office" from "somewhere else", not to point at one device.

## How long events are kept

| | Free | Starter | Pro | Enterprise |
| --- | --- | --- | --- | --- |
| Audit log page | No | No | Yes | Yes |
| Events kept | Up to a day | 30 days | 90 days | 365 days |

Events are recorded on every plan, and older ones are deleted every day. When you upgrade to Pro or Enterprise, you see what your previous plan still kept, for example the last 30 days after moving from Starter. After a downgrade, only what the new plan keeps is shown. See [Plans and limits](/en/docs/plans-and-limits#audit-log).

## Filters

Narrow the list by:

- **Action**: one of the groups above;
- **Member**: who did it;
- **Agent**: the agent it concerns;
- **Dates**: a range of days, in UTC.

The newest events come first, 50 at a time.

## Export as CSV

Download the events that match your filters as a CSV file, up to 10,000 rows, newest first. Each row has the time (UTC), who, the action, what happened in words, the target, the agent and the network.

- Cells that a spreadsheet would read as a formula (starting with `=`, `+`, `-` or `@`) are prefixed with an apostrophe, so opening the file never runs anything.
- Downloading the CSV is recorded in the audit log too.

## Limits

- There's no way to edit or delete events yourself. They go when your plan's retention ends, or with the account if the owner deletes it.
- The log isn't sent anywhere: no email, webhook or API for it. Use the CSV export.
