Access log
Who opened, downloaded or restored which file or record, from where, and through which channel.
The access log records who reached into the archive and what they touched.
Recording is off by default
Access recording is off by default. Nothing is recorded, and nothing appears in the table, until the Record access toggle is on. Switching it on does not backfill: entries only exist from the moment recording starts.
Retention
Retention sets how many days an entry is kept before it is dropped.
Access log entries live in the tenant database and count against the same single database allowance as your captured history. A longer window can fill that allowance without capturing a single extra record.
This is the trap worth naming plainly. Widening the access log window is not free, and it competes for the same gigabytes as your record history. Check Usage and limits before you widen it.
Reading an entry
| Column | What it tells you |
|---|---|
| Time | When the access happened, newest first, in UTC. |
| Action | What was done: View, Download, Restore or Share link download. |
| Actor | Who did it, and whether they are a User, an Api token or a Share link. |
| Target | The file or record that was reached. |
| File source | Where the file was served from. |
| Accessed via | The channel used, such as the web app, the API, a share link, or the ERP. |
| IP address | The address the request came from. |
| Outcome | Whether the access was Allowed or refused. |
Narrowing the list
The filter bar takes an actor or IP search plus six dropdowns: action, actor, target, file source, channel and outcome, and a date range with a start and end date.
Export
Export CSV takes the currently filtered view out as a file, which is the usual way to hand a period to an auditor without giving them access to the archive itself.