What is recorded in the audit log
The permanent record of who did what, how to search it, and how long it is kept.
Version 1.0 · Last updated
When you would do this
When you need to establish what happened: who approved something, when a setting changed, whether a payment was made by the person who says they made it.
Everyone can read the audit log, including Viewers.
What is recorded
Every significant action, with who did it and when:
- Payment requests created, cancelled, signed and executed
- Flags resolved, including the comment written and the documents attached
- Policy changes, quorum changes and wallet policy assignments
- Team changes: invitations sent, accepted, revoked, roles changed, members removed
- Wallets created and quarantine addresses created and archived
- Counterparties and addresses added, archived and restored
- Sign-ins, including sign-ins that used the fallback method rather than a passkey
- Emergency lock engaged and released
Steps
- Go to Governance › Audit log.
- Filter by date range, by category, by event type, or by the person who acted.
- Search if you know roughly what you are looking for.
- Open an entry for its full detail.
- Export if you need it outside the app.
What to expect
The audit log is read-only for everyone, including Admins. There is no edit and no delete. Nobody in your organisation, and nobody at Stablerail, can alter an entry after the fact.
Entries are retained for the life of your account.
Archiving something does not remove it from the audit log. An archived counterparty, address or quarantine address remains fully visible in the record.
If your memory of events and the audit log disagree, the audit log is the authority.
Using it well
For a specific transaction, it is usually faster to open the transaction in the Ledger and download its evidence pack, which assembles the audit trail for that payment along with the risk dossier, policy snapshot and documents into one file. See "Export an evidence pack".
Use the audit log itself when your question spans transactions: everything one person did last month, every policy change this year, every fallback sign-in.
Common problems and what they mean
You cannot find an event you expected. Widen the date range first. Timestamps are recorded when the action completed, which may differ from when it was started.
An action shows a name you do not recognise. Check your team list, including removed members. Removed members remain in the record for actions they took while active.
You want to correct an entry. You cannot. If something was recorded with a wrong explanation, add a correcting note on the relevant transaction rather than trying to change history.
