Audit Log
The workspace's own trail of privileged acts — who did what, to which resource, and when, to the minute. Filtering and counting stay in the database, so the total the caption gives is the honest one.
At a glance
- Who, What and Window filters as removable chips
- The matched total, counted in the database
- When to the minute, in workspace time
- Every filter pushed into the URL

The filter bar
The Who and What pickers are built from this workspace's own rows — they offer only people and actions the trail actually holds. A hand-edited query falls back to unfiltered rather than claiming an empty log. And the two empty states stay distinct: nothing matched is not nothing recorded.
The table
Rows page at 25. When lands to the minute in workspace time; Who pairs its label with a kind badge; What names the act; the resource draws its type over a monospace id. There is no export here — the Retention screen's workspace export is the one answer.
- Filter the trailWho, What and Window start at Anyone, Any action and Any time; Window also offers the last 7, 30 or 90 days. Active filters draw as removable chips, with Clear all beside them.
- Read the rowsFour columns: When to the minute in workspace time, Who as a label with a kind badge, What, and the resource type over its monospace id.
- Trust the countThe caption gives the matched total in words. Every control pushes a URL, and the database does the filtering and the counting — the number is never a guess.
