Ask a human
waxTable

Security & privacy

The audit log

The audit log is a tamper-evident record of significant actions in your workspace — who did what, and when — so you can review activity, settle questions and support compliance.

5 min readUpdated 18 Jun 2026

What the audit log is

The audit log records the meaningful things that happen in your workspace: who generated, edited, approved, sent or deleted a document, and when. It's the answer to "what actually happened here?" — without relying on anyone's memory.

Entries are append-only and tamper-evident. They're written as actions occur and aren't meant to be edited after the fact, which is what makes the log trustworthy for review and disputes.

What it records

The log focuses on actions that change state or carry accountability, rather than every keystroke.

Indicative categories — the exact events recorded may evolve as the product grows.
AreaExample events
DocumentsGenerated, edited, version approved, sent, deleted
ApprovalsSubmitted for sign-off, approved, rejected, routed
AccessMember invited, role changed, removed
AccountSensitive settings changed, MFA enabled

Reviewing activity

Use the log when you need to understand a sequence of events — for example, who changed a price before a proposal went out, or when a contract was approved.

  1. Open the log

    Find the audit or activity view for your workspace, available to members with the right role.

  2. Narrow to what you need

    Filter by person, document or time window to cut through the noise.

  3. Read the entry

    Each entry shows the actor, the action and the timestamp, so you can reconstruct what happened.

  4. Cross-check the document history

    For document-level changes, pair the log with the version history in the paged editor.

Using it for compliance

A reliable record of who approved and sent which document, and when, is exactly what auditors and clients ask for. The audit log gives you that evidence without extra bookkeeping.

  • Demonstrate that an internal sign-off happened before a document was sent.
  • Show the access history of a sensitive project.
  • Investigate after a staff change to confirm nothing was missed.
  • Support a client or regulator request with a factual timeline.

Good practice

The log is most useful when the underlying access is well-managed. Keep roles tight so each entry maps cleanly to a real person and responsibility.

Frequently asked questions

Can someone edit or delete audit entries to cover their tracks?

The log is append-only and tamper-evident — entries are written as actions occur and aren't designed to be altered afterwards. That's what makes it useful for review.

Who can see the audit log?

Access depends on role. See permissions and team members and roles for how that's controlled.

How long is activity kept?

Retention is part of how we run the service. For your organisation's specific needs, including export of a record, email support.

Does the log show document content?

It records that an action happened — who, what and when — rather than reproducing the document text. For content changes themselves, use the version history in the paged editor.

Can I export the audit log for an external review?

For an export to support an audit or compliance request, contact support and tell us the scope you need.

Still need a hand?

Waxe answers most questions right inside the app. For everything else, our team replies within one business day.

Email support