Runwork
All Features

Prove

Audit Logs

Know what every agent did, and when.

Every important action is logged with full context: who did what, when, and what changed. Query by user, entity, action, or time range. Compliance-ready out of the box.

What Audit Logs gives you

Complete Activity Log

All creates, updates, and deletes logged. Nothing escapes the audit trail.

Change Tracking

See old and new values for every change. Know exactly what was modified.

Actor Identification

Track who made each change: user, system, or automation.

Rich Metadata

IP addresses, user agents, request IDs. Full forensic context.

Queryable History

Filter by user, entity type, action, or time range. Find what you need fast.

Append-Only Records

Entries are written once and never edited. What happened stays as it was recorded.

Why Audit Logs matters

How Audit Logs works

Audit Logs in Runwork track every important action in your workspace with complete context. Every create, update, and delete operation on entities is logged automatically. Every team management action (invitations, permission changes, role assignments) is recorded. Authentication events, API calls, and system operations all flow into the audit log.

Change tracking captures both the old and new values for every modification. When someone updates a customer record, the audit log shows exactly what changed: which fields were modified, what the previous values were, and what they became. This level of detail is essential for debugging issues and understanding the complete history of any record.

Actor identification tracks who made each change. Was it a user action? An automation? An AI agent? An API call? The audit log distinguishes between actors, so you see what happened and who or what caused it.

Rich metadata provides forensic context. IP addresses, user agents, request IDs, and timestamps accompany each log entry. When investigating a security concern or debugging a problem, this metadata helps reconstruct exactly what happened and correlate events across systems.

The query interface enables fast investigations. Filter by user, entity type, action type, or time range. Find all changes a specific user made last week. See every modification to a particular customer record. Track all delete operations in the past month. Results are instant, even across large log volumes. Most importantly, the log is append-only. Entries are written once and are not edited afterwards, which is what makes them useful as evidence for compliance and security reviews.

Frequently Asked Questions

What actions are tracked in audit logs?
All important workspace actions are tracked: creates, updates, and deletes on entities; team management actions (invitations, permission changes); authentication events; API calls; automation executions; and system operations. Each log entry includes who performed the action, when, and the complete details of what changed.
Can I see what data was changed and its previous values?
Yes. Audit logs capture both old and new values for every modification. When a record is updated, you see exactly which fields changed, what the previous values were, and what they became. This detailed change tracking is essential for debugging and understanding data history.
How do I search and filter audit logs?
The query interface lets you filter by user, entity type, action type (create, update, delete), and time range. Find all changes a specific user made, track every modification to a particular record, or see all delete operations in a time period. Results are instant even across large log volumes.
Can audit log entries be changed after the fact?
No. The log is append-only, so entries are written once and are not edited afterwards. What you read is what was recorded at the time.

Use Cases

Compliance requirements Security investigations Change tracking Debugging issues

Related Features

See How Teams Use Audit Logs

Ready to try Audit Logs?

One shared cloud under the AI tools your team already uses.