Changes to records are recorded at field level: who changed it, when, what it was, and what it became.
What An Entry Holds
- The time
- The person, or System where no user was signed in
- The action
- The record type and which record
- The field
- The value before, and the value after
Automated changes - a workflow updating a record - appear as System, so an automated change is distinguishable from a person's.
Finding Something
Settings, Security, Audit Log. Search matches the person, the record type, the field name and the action, so you can approach from whichever end you know. Filter by action to narrow further.
The most recent 100 entries load. For anything older, ask us.
Exporting
Export writes what is loaded to a spreadsheet - time, person, action, record type, field, and the from and to values. Use it for an auditor or to attach to an incident record.
Caution
The export contains the loaded window, not the whole history. Handing it to an auditor as "the complete record" would be wrong. If you need a defined period, ask us rather than assuming the export covers it.
A Worked Example
A salary figure looks wrong.
- Search the field name, not the person - you may not know who did it.
- Read the before and after on the matching entry.
- Note the person and time.
- Export if this is going anywhere formal.
- Check whether that person should have been able to change it, in Permissions.
Step five is the one that turns an incident into a fix, because the answer is usually that a role was broader than intended.
What It Does Not Cover
Being clear about the limits:
- It records changes to records. Sign-in events are a different trail.
- It records what changed, not why. Where the reason matters, the platform captures it separately - change requests on employee records, decision notes on approvals.
- It is not a substitute for permissions. Knowing who did something afterwards is weaker than them not being able to do it.
Who Can Read It
Reading the audit log is its own permission, and it should be narrow. The log contains the before and after values of every field, including sensitive ones - so audit access is effectively read access to everything that has changed.
Common Questions
Can entries be edited or deleted? The trail is a record, not a working table. If it could be edited it would be worthless.
Why does an entry say System? An automation or a scheduled job made the change. See Automation Health in the Operations section for what ran.
Something is missing. The window is the most recent hundred entries. Older activity exists; ask us.
Can we get alerts on specific changes? Notification rules cover many events. For something specific, an automation can watch for it. See Notifications in the Settings section.
Did this answer your question?
No, ask a person