Audit log
The audit log is a record of every change a user of your Ledger account makes -- not just the security-sensitive ones. It exists so you (and, if you ever need it, an auditor) can answer "who did this, and when" without having to reconstruct it from memory or support tickets.
What gets logged
Every non-GET request that Ledger accepts and carries out -- every
POST, PATCH, and DELETE call your account makes to Ledger's API --
gets one audit-log entry, whether or not it ends up changing anything.
Requests Ledger refuses (for example invalid input, rate limits, or a
feature that is switched off) are not recorded. There is no hand-picked subset of
"the actions that matter to log": every non-GET call gets an entry,
including calls, like validating or previewing a candidate exception
rule, that write nothing else. Read-only (GET) requests (viewing the
device matrix, loading a report, exporting a file) are not logged here.
Today that includes, among others:
- Suppressing, unsuppressing, or acknowledging an exception (in bulk or one at a time)
- Creating, editing, or deleting a custom exception rule
- Validating or previewing a candidate exception rule (even when nothing else changes)
- Signing out
Each entry records who (the signed-in user), what (the action and the entity it acted on), and when -- in your own browser's local time when you view it here, stored in UTC underneath.
What detail does and doesn't capture
Each entry carries a small detail payload: the action's name, the
entity it changed, and a handful of specific, named fields relevant to
that action -- for example, a suppression's mode, duration, and reason.
detail is deliberately coarse, never a full before/after diff of
whatever was changed. A rule edit's audit entry tells you a rule was
edited, not a column-by-column comparison of its old and new definition.
This keeps every entry small and reviewable, rather than an unbounded
dump of whatever happened to be on the row that day. Anything that looks
like a secret (a token, an API key, a password) is additionally stripped
before it is ever written, as a second layer of protection on top of
detail being narrow to begin with.
Filtering and exporting
The audit log screen (linked from the home screen, alongside Exceptions and the other operational views) lets you filter by actor, action, entity type, and a since/until date range. Every filter you set is reflected in the page's URL, so a filtered view can be bookmarked or shared with a teammate the same way every other filtered screen in Ledger works.
Export follows the same CSV/XLSX conventions as every other view -- the exported rows are always exactly what your current filters show on screen, capped at the same 50,000-row limit. The audit log has no PDF export.
Retention
Audit-log entries are kept; they are not deleted automatically. The retention period will be stated on the Trust page once it is confirmed (see also data retention). Until then, nothing here should be read as a retention guarantee.