Docs / Obsidian Suite / For administrators
Audit log
Manage > Audit log records who did what in your organization: every sign-in, release, deletion, download and configuration change, with the person, the time and the real client IP address.
Using it
Search matches the actor, the action or the target. Entries for message actions link to the message. You see your organization's entries. Entries are kept for at least a year.
Action names
| Action | Recorded when |
|---|---|
login.password, login.password+totp, login.sso, login.magic, logout | Sign-ins by method, and sign-outs. |
quarantine.release, quarantine.delete | Mail released or deleted, by an administrator, the user, a digest link (digest:<address>) or the API (api:<token name>). Automatic releases after an AI hold are shown on the message instead (released by ai). |
report.spam, report.ham | Spam and not-spam reports. |
message.clawback, message.download | Clawback from mailboxes (actor ai when an async AI review triggered it); original message downloaded. |
list.allow, list.block, list.delete | Allow and block list changes. |
org.update | Organization settings saved. |
domain.add, domain.update, domain.delete, domain.dkim_generate, domain.relay_key | Domain changes. |
connector.add, connector.update, connector.delete | Connector changes. Secrets are never logged. |
user.create, user.update, user.password_change, user.mfa_enable, user.mfa_disable | Account changes. |
policy.save, policy.delete | Policy override changes. |
secure.create, secure.revoke | A secure message was created or withdrawn through the API. |
secure.verify, secure.open, secure.reply | A recipient proved their address, opened a secure message, or replied to it. |