Read the workspace activity log
The System activities page records who did what across the workspace - sign-ins, member changes, documents, templates, billing and settings - with filters and IP addresses.
Every administrative action in a workspace is written to one feed at Settings > System activities. Each row is a plain sentence naming the person, what they did and to whom, with the time and the IP address alongside. For evidence about a single document, the audit trail on that document is the place to look instead.
Who can do this
Workspace admins. Managers and Members never see the tab.
Read a row
Rows are sentences, not codes. You'll see lines like "Anita Shah invited Aarav Mehta (aarav@acme.com) as Member" or "Priya Nair changed the role of Jordan Lee from Member to Admin". Where a change has a before and after, both are printed, so a plan change or a seat change carries its old and new value in the same line.
The rest of the row is three columns:
| Column | What it holds |
|---|---|
| Activity | A category icon plus the sentence. The icon is colored by outcome, so removals and failures read differently from creations at a glance. |
| Date | When it happened, in your workspace timezone and date format. |
| IP address | Where the request came from, or a dash when there was none. |

What gets recorded
Twelve categories, each available as a filter:
| Category | Examples of what lands there |
|---|---|
| Documents | Sends, cancellations, deletions, scheduled sends dispatching or being rescheduled |
| Templates | Creation, publishing, duplication, archiving, sharing changes |
| Members | Invites sent, accepted and revoked, role changes, removals, join requests approved or declined |
| Teams | Teams created, renamed, deleted, and members added or removed |
| Contacts | Contacts added, edited and deleted |
| Folders | Folders created, renamed, moved and deleted |
| Custom fields | Custom field definitions created, edited, archived, restored, deleted |
| Bulk sends | Bulk send jobs started, scheduled, cancelled and dispatched |
| Billing | Plan changes, downgrades to Free, trial decisions, cancellation surveys |
| Workspace | Settings and branding updates, custom disclaimers, IP restrictions, API keys, webhook endpoints, sending addresses, workspace deletion and restore |
| Personal settings | Profile changes such as an avatar or a saved signature being added or removed |
| Sign-in & security | Sign-ins, failed sign-ins, sign-outs, password resets, email changes, two-factor setup and failures, revoked sessions |
That last category is the one most admins come for. A run of failed sign-ins from an address nobody recognizes, or a two-factor challenge failing repeatedly, shows up here before it shows up anywhere else.
Narrow the feed
Above the table sit three filters. Set them in any order, and they combine.
- Category limits the feed to one of the twelve groups above.
- Member limits it to one person's actions.
- Date range opens a calendar with Today, Last 7 days, Last 30 days, This month, Last month and All time down the side. You can also drag a custom range across the two months shown.

Clear filters appears as soon as any filter is set and resets all three. Results come 20 rows to a page, newest first, with a numbered pager underneath and a count telling you how many rows matched.
What happens next
There's nothing to maintain. The feed is written as people work and keeps its history for as long as the workspace exists, so a question about who changed a setting six months ago has an answer. Deleting the workspace for good removes its log along with everything else.
If something goes wrong
- "No activity yet" on a busy workspace. A filter is still applied. Click Clear filters.
- You can't find an action you know happened. Check the category first: template sharing sits under Templates, while a change to a sending address sits under Workspace.
- Times look wrong. The feed prints in the workspace timezone. Change it under Settings > Organization and the whole feed redraws.
- A member is missing from the Member filter. People who've been removed from the workspace drop out of the list, though their past rows stay in the feed with the name they had at the time.
Frequently asked questions
Who can see the activity log?
Workspace admins only. The tab does not render for Managers or Members, and the data behind it is refused to them as well. That keeps sign-in records and IP addresses away from people who have no business reviewing their colleagues' movements.
How is this different from a document's audit trail?
The audit trail belongs to one document and records what each recipient did with it, which is the evidence you would produce in a dispute. The activity log is workspace-wide administration - members, roles, settings, billing, templates - and covers actions no single document would ever show.
Can I export the log to a spreadsheet?
Not from this page. It is built for looking something up rather than for bulk analysis, so you filter, read and page through it in the app. Document-level reporting does export, and the reports page is where to go for send volumes and outcomes.
Why does a row say Someone instead of a name?
The action had no signed-in person behind it, or it was taken by an account that no longer resolves to a name. Automatic events such as a scheduled send dispatching itself are the common case. The category icon and the sentence still tell you what happened.
What is the IP address column for?
It records where the action came from, which matters most on sign-ins and failed sign-ins. An unfamiliar address next to a successful sign-in is worth asking about. A dash means the event had no request behind it, such as a scheduled job that ran on its own.
Keep going
Workspace roles - Admin, Manager, Member and billing
What each of the three workspace roles can do, who is allowed to change a role, and why the last admin cannot be demoted or removed.
ReadInvite teammates and manage seatsGrowth and up
Send an invite from Settings > Team, watch it move from Invited to Active, revoke the ones you no longer want, and see how seats are counted.
ReadWorkspace name, timezone and date format
Set the workspace name your recipients see, plus the timezone, date format and clock style every screen and emailed date uses.
ReadRead the audit trail and audit certificate
The Activity tab logs every action on an envelope while it is live. The Certificate of Completion turns that log into a signed record you can hand to a lawyer.
Read