AgentStack Docs

Audit logs

Investigate workspace changes with Enterprise audit history and exports.

Administrators and owners on Enterprise workspaces can view audit logs. Use Dashboard → Audit logs to investigate actions by user, resource, status, source, date, or free-text search. Results load in pages of 50 rows. Open a row to view its details. When necessary, copy identifiers or context from a row into an incident record.

Start an investigation with narrow filters: an approximate time range, the affected resource, and the expected actor or action. Narrow filters make the timeline easier to review. They also reduce the chance that a broad export hides the event you need. Audit history is a workspace administration tool, not a substitute for application-level logs from your own integrations.

Only an administrator or owner can export audit logs as a CSV file. The CSV export carries the current filters. An export stops at 50,000 rows. If you reach this limit, narrow the filters and create smaller evidence sets. Preserve exported data according to your own retention policy. Do not send raw logs to systems that do not need workspace identifiers or personal information.