← All features
Team & Enterprise

Activity audit log

Live

Immutable record of every action across the workspace.

What you get
  • Every action captured — uploads, edits, shares, AI runs, permission changes
  • Tamper-evident (append-only)
  • Filterable by user, date, type
  • CSV export
+1 more capabilities below
Overview

What it is.

Every action — uploads, edits, shares, downloads, AI runs, permission changes — is recorded in a tamper-evident log. Exportable to CSV for compliance audits and SOC 2 evidence.

Logs are workspace-scoped and admin-visible. Members see their own activity but not others'.

How it works

Three steps.
End to end.

01
1. Action happens

Any user action is logged with user, timestamp, IP, and action type.

02
2. Search + filter

Admin → Audit. Filter by user, date, action type, or document.

03
3. Export

CSV export for SOC 2, internal audit, or regulatory request.

Capabilities

What you get.

  • Every action captured — uploads, edits, shares, AI runs, permission changes
  • Tamper-evident (append-only)
  • Filterable by user, date, type
  • CSV export
  • Retention 12-36 months depending on action type
FAQ

Quick answers.

Can I forward audit events to my SIEM?

Enterprise plans support outbound webhooks for audit events — wire into Splunk, Datadog, or any HTTP endpoint.

Related

More in Team & Enterprise.

Workspaces
Live

One organisation, multiple workspaces with isolated data.

Roles & permissions
Live

Admin / Member / Guest with workspace-scoped and folder-scoped overrides.

Real-time collaboration
Live

Comment threads, @mentions, and review assignment inside any document.

Matter management
Live

Group contracts, court research, and compliance items by matter.

Want to try Activity audit log?
Get started in 60 seconds.

Sign up →All features