The audit log
A record of who did what, and the filters that make it usable when you need it.
The audit log is the answer to "who changed this". You'll ignore it for months and then need it urgently, which is the argument for knowing where it is before that happens.
Where to find it
What it records
Each entry carries When, Who, What happened, the Subject it happened to, the Client it relates to, the Source it came from, and a Severity.
Severity is the useful column. It separates routine activity from the events that would matter in an investigation — a credential revealed, a permission changed, a document exported.
Filtering
Filters for Anyone, Any type, Any category, Any client, Any severity, and Any app.
The last one matters as your firm grows. An action taken through the API looks different from one taken by a person clicking a button, and being able to separate them is how you tell an integration misbehaving from a colleague misunderstanding.
Columns are configurable, so you can build a view for the question you're actually asking.
When you'll use it
- A client asks who accessed their information.
- A document went somewhere it shouldn't have.
- Something changed and nobody remembers changing it.
- Somebody left and you're establishing what they touched.
In each case the value depends on the log having been running all along, which it has been.
Exporting
Export is a separate permission from viewing, and configuring the log and its retention is a third.
That split is deliberate. Reading the log is oversight. Exporting it produces a file of sensitive activity that then lives outside LedgerOS. Being able to change retention means being able to shorten how far back the record goes, which is the one action you'd least want widely held.
Notes and limits
- The log is firm-wide, not per client, though it can be filtered to one.
- Entries can't be edited or removed individually.
- Retention is configurable, under its own permission.
- The log records actions, not their content. It shows a document was exported, not what was in it.
