Open Chat Interfacedocs

Audit log and reports

Who did what and from where, what has been consumed, and usage summaries by email.

The audit log

Insights → Audit log (/admin/audit). Who did what, when, and from where.

Insights → Audit log in the auditor's read-only view: a search for "auth." over the last 7 days, with entries showing time, actor, action and target, Details, and Export.

What is recorded

  • Administrative actions: settings, models, providers, budgets, invitations, policies, announcements, connectors, webhooks, backups, compliance, bulk operations.
  • Authentication: sign-in, sign-up, sign-out, password reset and change, verification and single sign-on, including failures and attempts for accounts that do not exist, which is what makes a brute-force attempt visible. People's own changes in Settings → Account are recorded too: their name (auth.profile.updated) and signing devices out (auth.session.revoked, auth.sessions.revoked_others). Attempts refused by the sign-in limit are recorded as auth.rate_limited, once a minute per address or account.
  • Deletions: every conversation, file, project, memory note and account moved to the trash, restored or deleted, by the person, an administrator or a background job (conversation.trash, conversation.delete, attachment.delete, project.delete, memory.delete, user.delete and others). Each names what was deleted, whose it was and why, never its content; see deletion events. A refused attempt to delete one's own account (wrong password) is user.delete.failure.
  • Activity metadata: tool calls (tool.call), file exports (message.export, artifact.export), full exports and imports (user.export, user.import), connector connections, memory changes, revoking share links (share_link.revoke, share_link.revoke_all).

Only outcomes and metadata are recorded. No credentials, no tokens, no request bodies and no conversation content. Creating and changing projects, conversations and share links is personal content and is not written to the log; deleting them and revoking links is.

Searching it

Search, action family and date window are applied in the query, across everything retained, not just the page in front of you. Typing auth. in the action filter finds every authentication event. Searching an IP address finds everything that came from it, which is usually where an investigation starts. Entries link to the accounts they name.

Configuration changes

A settings entry records what a value was as well as what it became, so "who turned off single sign-on last Tuesday, and what was it before" has an answer. Secrets record only whether they were set, cleared or replaced.

Export

Export downloads CSV of everything matching the current filters, up to 50,000 rows. Filter first. For a continuous, complete copy, use the compliance export; for events as they happen, webhooks.

How long entries are kept, and which are kept regardless, is on Retention.

Usage

Insights → Usage (/admin/usage). Totals, daily volume, a breakdown by model and the heaviest consumers.

Insights → Usage, Spend tab over 30 days: total spend, messages, tokens and people, spend per day, and spend by model, including the embeddings and reranking models.
  • Token totals contain reported usage; cost is calculated from the prices copied onto each request when it was made. Neither includes amounts held by budget enforcement, and neither is a provider invoice.
  • Missing or incomplete reports are stored as unknown, not as zero.
  • Usage records carry no reference to a conversation.
  • Embeddings, reranking and summaries show under model names starting with embedding: and rerank:, and the conversation's model.
  • The reporting time zone is set on Retention.

Deleted accounts

Deleting an account, by an administrator or by the person, keeps its usage records (events, daily totals and limit refusals) without anything that identifies the person, so totals, the daily and per-model figures and scheduled reports do not change afterwards:

  • Top consumers and the scheduled report's Heaviest use show the usage of every deleted account as one Deleted accounts row, ranked with everyone else.
  • People (and Active people in reports) and people affected on the Limits tab count accounts that still exist; a deleted person's usage stays in every other figure.
  • A person's own usage meter and their page under People never include it.
  • Usage history retention prunes these records by age like any other.
Insights → Usage, Top consumers: named people and one "Deleted accounts" row ranked among them.

Usage records of accounts deleted before v0.10 were removed at the time and cannot be recovered.

Use this page before setting a budget: a limit chosen from observed use lands better than one chosen from an assumption.

Scheduled reports

Insights → Reports (/admin/reports). A usage summary by email, daily, weekly or monthly. Send the monthly summary to whoever asks about spend and the questions stop.

Insights → Reports: a monthly usage summary with its recipients, last send and Send due now.
  • Due-ness is decided from the last send, not a calendar expression: a replica that was down over a boundary sends once when it returns rather than skipping the period.
  • Send due now lets you check recipients and content without waiting a month.
  • A failure is recorded on the report, not only in the logs.
  • Reports need email delivery. Without it none arrive: the page warns, enabling a report makes email a required step on the setup checklist, and System health reports email as not configured.

When someone reports a problem

  1. System health: is something actually broken?
  2. The audit log, filtered to their address: what did they do, and what happened?
  3. Their account page: are they at a limit? Do their sessions look right?
  4. Usage: has something changed instance-wide, or only for them?

On this page