Audit Log
View and filter the complete audit trail of all platform actions.
Audit Log
The audit log is a complete, immutable record of every action taken on your CrownSync Playbooks organisation. Every view, edit, export, login, invitation, revocation, and settings change is logged with full details. The audit log is essential for demonstrating compliance with ISO 27001, Cyber Essentials, UK GDPR, and sector-specific regulatory requirements.
Immutable by Design
The audit log is append-only. Records cannot be edited, deleted, or tampered with by any user, including the organisation Owner. This immutability ensures the audit trail is trustworthy evidence for regulators, auditors, and legal proceedings.
What Is Logged
Every significant action on the platform generates an audit log entry. The following categories of actions are recorded:
- Authentication— Sign-in, sign-out, failed login attempts, MFA verification (for external collaborators)
- Playbook access— Viewing a playbook, opening a specific section, navigating between phases
- Content changes— Editing sections, publishing drafts, reverting to previous versions, customising communication templates
- Exports— PDF generation, batch exports, print actions, with verification IDs
- Incidents— Declaring incidents, updating severity, logging actions, attaching evidence, closing incidents
- Drills— Starting drills, completing drill phases, generating drill reports
- Team management— Inviting members, changing roles, removing members, invitation acceptance
- Collaborator management— Inviting collaborators, assigning sections, revoking access, MFA resets
- Settings changes— Organisation profile updates, PDF branding changes, integration configuration
- Comments— Adding, replying, resolving, and reopening comments
Log Entry Details
Each audit log entry contains the following information:
- Timestamp— The exact date and time the action occurred, in UTC
- User— The name and email of the person who performed the action
- Action— The action code (e.g. SECTION_EDITED, PDF_EXPORTED, MEMBER_INVITED)
- Resource— The playbook, section, member, or other resource affected
- Details— Additional context, such as the verification ID for exports or the role assigned for invitations
- IP address— The IP address from which the action was performed
Filtering the Audit Log
The audit log can be filtered to help you find specific entries:
- By user— Show actions by a specific team member or external collaborator
- By action type— Filter to a specific category such as exports, logins, or content changes
- By date range— Show entries within a specific time period
- By resource— Filter to actions on a specific playbook or section
You can also use the search field to find entries matching specific text, such as a playbook name, email address, or verification ID.
CSV Export
The audit log can be exported as a CSV file for use in external reporting tools, spreadsheets, or compliance documentation. To export:
- Apply any filters you need to scope the export
- Click the Export CSV button
- The download begins automatically
The CSV export includes all columns visible in the audit log table. Filters are applied to the export, so you can export a specific date range, user, or action type rather than the entire log.
GDPR Considerations
The audit log contains personal data (names, email addresses, IP addresses) as required for legitimate security and compliance purposes. Under UK GDPR, this processing is justified under Article 6(1)(f) — legitimate interests — for security monitoring and regulatory compliance.
Audit log entries relating to a specific individual are included in Subject Access Requests (SARs). However, audit log records cannot be deleted under the right to erasure when retention is necessary for compliance with legal obligations or the defence of legal claims.
Retention Period
Audit log entries are retained for the lifetime of the organisation account. If the organisation is deleted, audit log data is retained for an additional period as required by applicable regulations before being permanently removed.
Was this page helpful?