Audit log
Who did what across your workspace — sign-ins, admin changes, and support access, filterable and reviewable.
Administration → Audit Log answers the governance question every admin eventually asks: who did what, and when. In the product’s words: “Review who did what across your workspace — sign-ins, admin changes, and break-glass access.”
SaaS tiers: the Audit Log is “Available on Professional and Enterprise plans.” In Community it is simply available.
Reading the log
Each event is a row: When, Actor, Action, Target. Filter by action name to narrow the stream (“Filter by action…”).
The Actor column distinguishes three sources:
- A named user — someone in your organization.
- System — Orkyo itself (automated lifecycle actions).
- Orkyo Support, with a Platform badge — support staff acting via break-glass access. Break-glass sessions are also visible in-app as a persistent banner while active, so support access is never silent.
What lands here
Security-relevant and administrative activity: sign-ins, role changes, invitations, organization-level changes, reporting-token lifecycle, and support access. Day-to-day planning edits (scheduling a request, editing a space) are product data, not audit events — the log is for accountability, not activity tracking.
Using it well
- Establish a review rhythm for admin-heavy periods — onboarding waves, offboarding, incident follow-ups.
- Filter by action first — action names are stable identifiers, the fastest path to “all role changes this month”.
- Correlate with Users — an unexpected role change in the log has its current state on the Users tab.