> This page is for Data API, version v2 (default).
> For other versions, use one of these documentation indexes:
> - v2 (default): https://developers.webflow.com/data/v2.0.0/llms.txt
> - v2 Beta: https://developers.webflow.com/data/v2.0.0-beta/llms.txt
> - v1: https://developers.webflow.com/data/v1.0.0/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.webflow.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.webflow.com/_mcp/server.

# Workspace audit log event types

> Review the event types and payloads for the Workspace Audit Logs API.

## Actor

Every event includes an `actor` object that identifies who performed the action. Use the `type` field to tell a user apart from an API token.

| Field   | Type   | Description                                                                                                       |
| ------- | ------ | ----------------------------------------------------------------------------------------------------------------- |
| `type`  | string | The kind of actor, enum: `person`, `token`                                                                        |
| `id`    | string | For `person`, the user's ID, which may be `null`. For `token`, the ID of the token's authorization, not a user ID |
| `email` | string | The user's email address. Only present when `type` is `person`                                                    |
| `name`  | string | The API token's name, if it has one. Only present when `type` is `token`                                          |

A `token` actor means an API token made the change on its own behalf, without a signed-in user.

## `user_access`

Login and logout events for users in the workspace.

##### Event subtypes

| Value    | Description       |
| -------- | ----------------- |
| `login`  | A user logged in  |
| `logout` | A user logged out |

#### Payload schema

| Field       | Type   | Description                                                       |
| ----------- | ------ | ----------------------------------------------------------------- |
| `method`    | string | How the user logged in, enum: `dashboard`, `sso`, `api`, `google` |
| `location`  | string | The geolocation based on the logged IP address                    |
| `ipAddress` | string | The captured IP address of the user                               |

## `custom_role`

Tracks when custom roles are created, updated, or deleted in your workspace. [Learn more about custom roles](https://help.webflow.com/hc/en-us/articles/37207901526419-Create-and-manage-custom-roles).

##### Event subtypes

| Value          | Description                    |
| -------------- | ------------------------------ |
| `role_created` | A custom role has been created |
| `role_updated` | A custom role has been updated |
| `role_deleted` | A custom role has been deleted |

#### Payload schema

| Field              | Type   | Description                          |
| ------------------ | ------ | ------------------------------------ |
| `roleName`         | string | The name of the custom role          |
| `previousRoleName` | string | The previous name of the custom role |

## `workspace_membership`

Tracks when users join or leave the workspace, and when their roles change within it.

##### Event subtypes

| Value               | Description                                |
| ------------------- | ------------------------------------------ |
| `user_added`        | A user has been added to the workspace     |
| `user_removed`      | A user has been removed from the workspace |
| `user_role_updated` | A user's role has been updated             |

#### Payload schema

| Field              | Type   | Description                                                                                          |
| ------------------ | ------ | ---------------------------------------------------------------------------------------------------- |
| `targetUser`       | object | The affected user, with properties `id` and `email`                                                  |
| `method`           | string | How access was managed, enum: `sso`, `dashboard`, `admin`, `access_request`, `api`, `invite`, `scim` |
| `userType`         | string | Type of user, enum: `member`, `guest`, `reviewer`, `client`                                          |
| `roleName`         | string | The role assigned to the user                                                                        |
| `previousRoleName` | string | The previous role (for role updates)                                                                 |

## `site_membership`

Tracks when users are added to or removed from a specific site, and when their site-specific roles change or their granular access to resources. This is similar to workspace membership events, but focused on site-level access instead of workspace-level access.

##### Event subtypes

| Value                          | Description                                                       |
| ------------------------------ | ----------------------------------------------------------------- |
| `user_added`                   | A user has been added to a site                                   |
| `user_removed`                 | A user has been removed from a site                               |
| `user_role_updated`            | A user's site role has been updated                               |
| `user_granular_access_updated` | A user's granular access has been updated for a specific resource |

#### Payload schema

| Field              | Type   | Description                                                                                                                                  |
| ------------------ | ------ | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `site`             | object | The affected site, with properties `id` and `slug`                                                                                           |
| `targetUser`       | object | The affected user, with properties `id` and `email`                                                                                          |
| `method`           | string | How access was managed, enum: `invite`, `scim`, `dashboard`, `admin`, `access_request`, `api`. `scim` appears only on `user_removed` events. |
| `userType`         | string | Type of user, enum: `member`, `guest`, `reviewer`, `client`                                                                                  |
| `roleName`         | string | The role assigned to the user                                                                                                                |
| `previousRoleName` | string | The previous role (for role updates)                                                                                                         |
| `granularAccess`   | object | The granular access settings for the user, with properties `id`, `name`, `type`, `restricted`                                                |

## `workspace_invitation`

Tracks the lifecycle of workspace invitations from when they're sent to when they're accepted, declined, or canceled.

##### Event subtypes

| Value                     | Description                                                                                                                               |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| `invite_sent`             | A workspace invite was sent                                                                                                               |
| `invite_accepted`         | A workspace invite was accepted                                                                                                           |
| `invite_role_updated`     | The role on a workspace invite was updated                                                                                                |
| `invite_canceled`         | A workspace invite was canceled                                                                                                           |
| `invite_declined`         | A workspace invite was declined                                                                                                           |
| `access_request_accepted` | A [guest access request](https://help.webflow.com/hc/en-us/articles/33961349456915-Agency-or-Freelancer-guest-role-overview) was accepted |
| `access_request_declined` | A [guest access request](https://help.webflow.com/hc/en-us/articles/33961349456915-Agency-or-Freelancer-guest-role-overview) was declined |

#### Payload schema

| Field              | Type   | Description                                                                                                                                                                       |
| ------------------ | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `targetUser`       | object | The invited user, with properties `id` and `email`                                                                                                                                |
| `method`           | string | How the invitation was managed, enum: `sso`, `dashboard`, `admin`, `api`, `designer`, `scim`, `access_request`                                                                    |
| `userType`         | string | Type of user invited, enum: `member`, `guest`, `reviewer`, `client`                                                                                                               |
| `roleName`         | string | The role assigned to the user in the invitation                                                                                                                                   |
| `previousRoleName` | string | The previous role (for updated invitations)                                                                                                                                       |
| `targetUsers`      | array  | List of users approved from a [guest access request](https://help.webflow.com/hc/en-us/articles/33961349456915-Agency-or-Freelancer-guest-role-overview) with an `id` and `email` |

## `workspace_setting`

Tracks changes to Workspace settings.
Currently, this event is triggered only when the AI enablement setting changes, not on any other Workspace setting changes.

##### Event subtypes

| Value             | Description       |
| ----------------- | ----------------- |
| `setting_updated` | A setting changed |

#### Payload schema

| Field           | Type   | Description                                             |
| --------------- | ------ | ------------------------------------------------------- |
| `method`        | enum   | How the value was changed: `dashboard`                  |
| `previousValue` | string | The previous value of the setting                       |
| `setting`       | enum   | An identifier for the setting that changed: `ai_toggle` |
| `value`         | string | The new value of the setting                            |