Skip to main content
Audit logs track configuration, permission, and security changes made within your incident.io account, so you have a record of who changed what and when. Available on the Enterprise plan, powered by WorkOS, with entries retained for one year.
You need the View audit logs permission, which Owners and Admins have by default. You can also grant it to a custom role.

What’s tracked

Audit logs cover configuration, permission, and security events. They record:
  • Alert sources, routes, priorities, and escalation paths
  • Schedules, schedule overrides, and holiday feeds
  • Custom fields, incident types, roles, statuses, timestamps, and severities
  • Workflows, nudges, announcement rules, post-incident tasks, and post-mortem templates
  • Status pages, policies, and Catalog types
  • User creation, updates, deactivation, logins, and role assignments
  • SCIM group role and seat mappings
  • API key creation, rotation, and deletion
  • Integration installs and uninstalls, IP allowlist changes, and secrets
  • Access attempts, access requests, and membership changes on private incidents, alerts, and escalations
  • Telemetry data source installs, access mode changes, and queries
  • Insights measures, drilldowns, and exports that include private incident data
  • Timeline items you delete, and incident, alert, or escalation data you scrub
Day-to-day incident work is recorded in each incident’s activity log rather than here. Use the incident activity log API to pull that history into your own systems. Each entry records the actor (person or system making the change), the target (what was modified), and contextual details like location and user agent. Entries follow a versioned schema, so older entries stay parseable. See the audit log entry schema for every entry type and its fields.

Viewing audit logs

Access audit logs at Settings → Security. From there you can:
  • View entries in a web interface, filterable by target, event type, actor, and date
  • Export entries for a given time period to CSV
  • Set up a log stream to a SIEM provider (e.g. Datadog, Splunk, or an Amazon S3 bucket)
Entries reach you by log stream or CSV export rather than through the API.

Retention

We keep entries for one year. Stream or export anything you need to keep for longer. Audit logs start on April 18, 2023.