Workspace audit log event types
Monitor and debug workspace activity with detailed audit logs. Each event captures who did what, when, and how - from user logins to role changes. Explore the available event types and their Payload schemas below.
Actor
Every event includes an actor object that identifies who performed the action. Use the type field to tell a user apart from an API token.
A token actor means an API token made the change on its own behalf, without a signed-in user.
user_access
Login and logout events for users in the workspace.
Event subtypes
Payload schema
custom_role
Tracks when custom roles are created, updated, or deleted in your workspace. Learn more about custom roles.
Event subtypes
Payload schema
workspace_membership
Tracks when users join or leave the workspace, and when their roles change within it.
Event subtypes
Payload schema
site_membership
Tracks when users are added to or removed from a specific site, and when their site-specific roles change or their granular access to resources. This is similar to workspace membership events, but focused on site-level access instead of workspace-level access.
Event subtypes
Payload schema
workspace_invitation
Tracks the lifecycle of workspace invitations from when they’re sent to when they’re accepted, declined, or canceled.
Event subtypes
Payload schema
workspace_setting
Tracks changes to Workspace settings. Currently, this event is triggered only when the AI enablement setting changes, not on any other Workspace setting changes.