Obsidian SuiteDocumentation
Obsidian Suite: all chapters

Docs / Obsidian Suite / For administrators

Audit log

Manage > Audit log records who did what in your organization: every sign-in, release, deletion, download and configuration change, with the person, the time and the real client IP address.

Using it

Search matches the actor, the action or the target. Entries for message actions link to the message. You see your organization's entries. Entries are kept for at least a year.

Action names

ActionRecorded when
login.password, login.password+totp, login.sso, login.magic, logoutSign-ins by method, and sign-outs.
quarantine.release, quarantine.deleteMail released or deleted, by an administrator, the user, a digest link (digest:<address>) or the API (api:<token name>). Automatic releases after an AI hold are shown on the message instead (released by ai).
report.spam, report.hamSpam and not-spam reports.
message.clawback, message.downloadClawback from mailboxes (actor ai when an async AI review triggered it); original message downloaded.
list.allow, list.block, list.deleteAllow and block list changes.
org.updateOrganization settings saved.
domain.add, domain.update, domain.delete, domain.dkim_generate, domain.relay_keyDomain changes.
connector.add, connector.update, connector.deleteConnector changes. Secrets are never logged.
user.create, user.update, user.password_change, user.mfa_enable, user.mfa_disableAccount changes.
policy.save, policy.deletePolicy override changes.
secure.create, secure.revokeA secure message was created or withdrawn through the API.
secure.verify, secure.open, secure.replyA recipient proved their address, opened a secure message, or replied to it.