All help topics
Team and workspace

Read the workspace activity log

The System activities page records who did what across the workspace - sign-ins, member changes, documents, templates, billing and settings - with filters and IP addresses.

Updated Open in app

Every administrative action in a workspace is written to one feed at Settings > System activities. Each row is a plain sentence naming the person, what they did and to whom, with the time and the IP address alongside. For evidence about a single document, the audit trail on that document is the place to look instead.

Who can do this

Workspace admins. Managers and Members never see the tab.

Read a row

Rows are sentences, not codes. You'll see lines like "Anita Shah invited Aarav Mehta (aarav@acme.com) as Member" or "Priya Nair changed the role of Jordan Lee from Member to Admin". Where a change has a before and after, both are printed, so a plan change or a seat change carries its old and new value in the same line.

The rest of the row is three columns:

ColumnWhat it holds
ActivityA category icon plus the sentence. The icon is colored by outcome, so removals and failures read differently from creations at a glance.
DateWhen it happened, in your workspace timezone and date format.
IP addressWhere the request came from, or a dash when there was none.

The System activities page showing the filter row and recent workspace events

What gets recorded

Twelve categories, each available as a filter:

CategoryExamples of what lands there
DocumentsSends, cancellations, deletions, scheduled sends dispatching or being rescheduled
TemplatesCreation, publishing, duplication, archiving, sharing changes
MembersInvites sent, accepted and revoked, role changes, removals, join requests approved or declined
TeamsTeams created, renamed, deleted, and members added or removed
ContactsContacts added, edited and deleted
FoldersFolders created, renamed, moved and deleted
Custom fieldsCustom field definitions created, edited, archived, restored, deleted
Bulk sendsBulk send jobs started, scheduled, cancelled and dispatched
BillingPlan changes, downgrades to Free, trial decisions, cancellation surveys
WorkspaceSettings and branding updates, custom disclaimers, IP restrictions, API keys, webhook endpoints, sending addresses, workspace deletion and restore
Personal settingsProfile changes such as an avatar or a saved signature being added or removed
Sign-in & securitySign-ins, failed sign-ins, sign-outs, password resets, email changes, two-factor setup and failures, revoked sessions

That last category is the one most admins come for. A run of failed sign-ins from an address nobody recognizes, or a two-factor challenge failing repeatedly, shows up here before it shows up anywhere else.

Narrow the feed

Above the table sit three filters. Set them in any order, and they combine.

  • Category limits the feed to one of the twelve groups above.
  • Member limits it to one person's actions.
  • Date range opens a calendar with Today, Last 7 days, Last 30 days, This month, Last month and All time down the side. You can also drag a custom range across the two months shown.

The Category dropdown open over the activity feed

Clear filters appears as soon as any filter is set and resets all three. Results come 20 rows to a page, newest first, with a numbered pager underneath and a count telling you how many rows matched.

What happens next

There's nothing to maintain. The feed is written as people work and keeps its history for as long as the workspace exists, so a question about who changed a setting six months ago has an answer. Deleting the workspace for good removes its log along with everything else.

If something goes wrong

  • "No activity yet" on a busy workspace. A filter is still applied. Click Clear filters.
  • You can't find an action you know happened. Check the category first: template sharing sits under Templates, while a change to a sending address sits under Workspace.
  • Times look wrong. The feed prints in the workspace timezone. Change it under Settings > Organization and the whole feed redraws.
  • A member is missing from the Member filter. People who've been removed from the workspace drop out of the list, though their past rows stay in the feed with the name they had at the time.
FAQ

Frequently asked questions

Who can see the activity log?

Workspace admins only. The tab does not render for Managers or Members, and the data behind it is refused to them as well. That keeps sign-in records and IP addresses away from people who have no business reviewing their colleagues' movements.

How is this different from a document's audit trail?

The audit trail belongs to one document and records what each recipient did with it, which is the evidence you would produce in a dispute. The activity log is workspace-wide administration - members, roles, settings, billing, templates - and covers actions no single document would ever show.

Can I export the log to a spreadsheet?

Not from this page. It is built for looking something up rather than for bulk analysis, so you filter, read and page through it in the app. Document-level reporting does export, and the reports page is where to go for send volumes and outcomes.

Why does a row say Someone instead of a name?

The action had no signed-in person behind it, or it was taken by an account that no longer resolves to a name. Automatic events such as a scheduled send dispatching itself are the common case. The category icon and the sentence still tell you what happened.

What is the IP address column for?

It records where the action came from, which matters most on sign-ins and failed sign-ins. An unfamiliar address next to a successful sign-in is worth asking about. A dash means the event had no request behind it, such as a scheduled job that ran on its own.

Related

Keep going

Did not find what you needed?Send us a message