# Audit log: see who changed what in your organization

> The audit log in Vimonto Deploy records who created, changed or removed what, and when, with the IP address. Search it, filter it by type and export it as CSV.

The audit log is a record of what people do in an organization: who created, changed or removed a server, site, database, member or other item, who deployed, restored a backup or opened a terminal, and when. It answers questions like "who deleted this database?" or "when was this role changed?".

You find it under **Settings** → **Audit log**. Entries are kept for a year, and secrets such as passwords and tokens are never logged.

![The audit log with what changed, who did it, the IP address and when](https://ops.vimonto.com/docs-media/en/audit-log.webp?v=161e760d "The audit log of an organization")

## What is recorded?

Every entry says what happened (**What**), who did it (**Who**) and when (**When**). Two kinds of actions are recorded.

**Creating, changing and removing things**, such as:

- servers, sites, databases and database users,
- firewall rules, SSH keys, processes, scheduled jobs and certificates,
- backups, monitors, heartbeats, site features and load balancer servers,
- site commands that were run, redirects and security rules (without their passwords),
- recipes, teams, members and invitations,
- integrations: cloud and DNS accounts, Git connections and storage,
- the organization itself, for example a new name.

For a change, the entry also lists the fields that changed with their old and new value, for example "PHP version: 8.3 → 8.4". Fields have the name you know from the form, in your language, in the table and in the export. The table shows up to four changed fields; the export has all of them. When a secret changes, such as a password, the entry only shows that it changed (`••••`), never the value.

**Actions**, such as:

- deploying a site and rolling it back,
- viewing a site's environment file, or restoring an earlier version of it,
- opening a terminal on a server, with the user it logged in as,
- deleting a server, and whether it was also deleted at its provider,
- offering a server to someone else, cancelling that, and the server leaving or joining the organization,
- running a backup, restoring one and downloading one,
- running a recipe, with the servers it ran on,
- billing: starting an upgrade, cancelling and resuming Premium, changing the billing details, and adding a card, making it the default or removing it (a card shows only its brand and last four digits).

Only what people do is recorded, in the browser or through the [API](https://ops.vimonto.com/docs/more/api). Work that Vimonto Deploy does by itself, such as scheduled backups or provisioning steps, is not; you follow that on the [activity](https://ops.vimonto.com/docs/organization/activity) page.

## Search and filter the audit log

- Use the search field to find entries by the person or by the name of what changed, for example a domain or a database name.
- Use the type filter to show one kind of item, such as only servers or only members. **Everything** shows all entries. The filter lists the types that occur in your organization's log.
- Sort by **When** by clicking the column header. The newest entries come first.

The list updates itself while people work.

## Who did it: people, API tokens and deleted users

The **Who** column shows the name of the person. When they used an API token, the name of the token is shown below it ("API token GitHub Actions"), so you can tell scripts and CI pipelines apart from work in the browser.

The name is stored with each entry, so it stays in the log after the person leaves the organization. When someone deletes their account, their entries stay but show **Deleted user** instead of their name.

## IP addresses

Each entry stores the IP address and the browser it came from. Owners and administrators see the **IP address** column, in the list and in the export; other members don't. The browser is not shown in the audit log; it is only included when a person [downloads their own data](https://ops.vimonto.com/docs/more/account).

## Export the audit log as CSV

Click **Export CSV** at the top of the page. You get a CSV file of the entries that match your current search and filter, newest first, with the columns **When**, **Who**, **Via** (the API token, if one was used), **What**, **Event** (the technical name, such as `site.deployed`), **Changes** and, for owners and administrators, **IP address**.

## Who can see the audit log?

Every member of the organization can open the audit log. A member who is limited to the servers of their [teams](https://ops.vimonto.com/docs/organization/teams) only sees entries about those servers, plus entries that don't belong to a server, such as changes to members or teams.

## How long is the audit log kept?

Entries are kept for **365 days** and then deleted automatically. When an organization is deleted, its audit log is deleted with it.

## Frequently asked questions

### Can someone remove or edit an entry?

No. There is no way to edit or delete entries in the app; they are only removed after a year, or with the organization.

### Is a deleted server still in the log?

Yes. Entries keep the name of the server or site they were about, also after it was removed.

### What is the difference between the audit log and activity?

The audit log shows what people changed and is kept for a year. [Activity](https://ops.vimonto.com/docs/organization/activity) shows the background tasks that do the work, with their steps and output, and is kept for 90 days.

### Does the audit log record what I type in the terminal?

No. Opening a terminal is recorded, with the server and the user it logged in as, but your keystrokes are never stored. See [terminal](https://ops.vimonto.com/docs/servers/terminal).
