---
title: "Review the organization audit log"
description: "How to find out who changed something in IoTFlows, when, and what the value was before. The organization audit log lives at /logs and holds one row per change, with a Log message, a color-coded Event chip, and a date. Three filters narrow it: a Users picker, a date range that takes effect on Apply, and a free-text search that matches identifiers as well as words. Selecting a row opens the Log Information modal, which shows the request payload and the record Before and After the change as raw JSON. There is no export. A work order's Activity Logs tab is the same log filtered to that work order, and is the only version the mobile apps reach."
category: "Audit"
source_url: "https://www.iotflows.com/docs/admin/audit-log/"
---
# Review the organization audit log

Find out who changed something, when they changed it, and what the value was before.

**You need to be an Organization Owner or Organization Administrator.** See [Roles and permissions](/docs/admin/roles-reference/#roles). **Web only**, with one exception: the [per-work-order history](#work-order) is the version the mobile apps reach.

An *audit log* is a record of the changes people made, one row per change. IoTFlows writes an entry every time someone creates, edits, or deletes something in your organization, and keeps a copy of the record as it stood before the change and after it.

Use the log to answer "when did this change", not "what is the current state". Rebuilding a machine's current configuration out of a stack of entries is slower and less reliable than opening the machine and reading it. You do not need the log for a value you can read off the screen that owns it.

## Open the log
Select **Logs** in the top navigation, or go to `/logs`. Each row of the table is one change.

| Column | What it holds |
|---|---|
| **Log** | A sentence naming the member and what they changed |
| **Event** | A chip naming the kind of change. The color comes from the server, so one kind of event is always one color |
| **Date** | When the change was made, as `2:41pm  9/18/25` |

The table pages 25 rows at a time. The footer above and below it reads the position in the result, for example `1 - 25 of 213`, with arrows either side to move a page.

![The Logs page at /logs, with Logs selected in the product nav. A dashed Users pill sits at the top left and a date-range button reading 9/15/2026 - 9/21/2026 at the top right, a full-width Search field under them, and below that a table with Log, Event, and Date columns. Fourteen rows are in view, each a sentence naming the member and what they changed, an amber Modified chip, and a timestamp. A header above the table reads 1 - 25 of 1000 with previous and next arrows. Nothing on the page offers a download](/images/admin/adm-log-01.webp)

*The organization audit log. There is no export.*

There is no export. The log cannot be downloaded as a CSV and cannot be emailed, so copying the rows you need out of the browser is the only way to take them anywhere else. See [What has no export](/docs/monitoring/exports-reference/#no-export).

## Filter by user
1. Select the dashed **Users** pill at the top left.
2. Type into **Search users...** to narrow the list by name, email, or username.
3. Select each member whose changes you want. A blue check marks the row.
4. Select **Apply**.

The pill then carries a count of the members you picked, for example **Users 2**, and the table reloads against that set. To drop the filter, reopen the pill and select **Clear**, or select the circle at the left of the pill.

![The filter row of the Logs page with all three filters set. Marked 1, the dashed Users pill carries the count 1 for the one member picked. Marked 2, the date-range button reads 9/15/2026 - 9/21/2026, with its picker open below on a list of presets, a days up to today box, two date fields, a September calendar with the week of the 20th selected, and an Apply button. Marked 3, the full-width Search field holds the word status, and the rows behind the picker all carry the word status](/images/admin/adm-log-02.webp)

*Filtering the log by user, date range and free text.*

Every filter is written into the address bar, as `users`, `from`, `to`, and `text`. A filtered log is therefore a link: paste the URL into a ticket and the person who opens it lands on the same rows.

## Filter by date range
The button at the top right reads the range it will request, for example `9/15/2025 - 9/21/2025`.

1. Select the button to open the calendars.
2. Pick a preset from the left column: **This Week**, **Last Week**, **This Month**, **Last Month**, **This Year**, or **Last Year**. You can instead type a number of `days up to today`, or select a start day and an end day on the two calendars.
3. Select **Apply**.

The calendars stop at tomorrow, so you cannot ask for a future range.

> **Warning:**
> **The table is empty. Where did the entries go?**
>
> Check the date range before anything else. On first load the button reads the last seven days, but no range has been sent yet, so the table holds whatever window the server returns by default.
>
> Selecting **Apply** is what puts a range on the request, and a range that ends before the change you are looking for returns nothing. A **Users** filter left applied from an earlier visit is the second thing to check.

## Search the text
The **Search...** field runs under the two filters and re-runs the query on each keystroke. It matches the text of the entry, identifiers included, so pasting a work order's or a machine's identifier returns every entry that touched that record.

### Log filters
| Filter | Accepts | Notes |
|---|---|---|
| **Users** | One or more members, picked from a checkbox list | Search the list by name, email, or username. Takes effect on **Apply**. Written to the URL as `users`, once per member |
| Date range | A start day and an end day, from a preset, the `days up to today` box, or the calendars | Takes effect on **Apply**. Nothing later than tomorrow. Written to the URL as `from` and `to` |
| **Search...** | Free text | Runs as you type, with no **Apply**. Matches identifiers as well as words. Written to the URL as `text` |

The three combine. Picking two members, a one-week range, and the word `downtime` returns only the entries that satisfy all three.

## Read the before-and-after diff
A *diff* is the same record shown twice, as it stood before a change and as it stood after, so you can compare the two.

Select any row. The **Log Information** modal opens on the entry's message and two panes of raw JSON:

| Pane | What it holds |
|---|---|
| **Before** | The whole record as it stood before the change |
| **After** | The whole record as it stood after it |

Both panes hold the entire record, not only the fields that moved, so read them side by side and find the key that differs. The keys are the API's field names rather than the labels on the screen where the change was made, so a machine's display name reads `asset_custom_name`.

Not every entry shows a difference. Entries that created a record carry the same JSON in both panes, and so do some status toggles, where the log records the record as it ended up rather than as it stood a moment earlier. On those, the row's own sentence is the record of what changed.

![The Log Information modal. The entry's message, that a member modified the shock threshold of a SenseAi sensor to 2, sits at the top, and below it two panes side by side headed Before and After, each holding the same sensor record as syntax-highlighted JSON, scrolled to the same line. An arrow points at node_shock_threshold in the After pane, which reads 2 where the Before pane reads 4. A Cancel button closes the modal](/images/admin/adm-log-03.webp)

*The before-and-after diff for one change.*

> **Info:**
> **Why does the close button say Cancel?**
>
> Nothing in **Log Information** is editable and there is nothing to save, so **Cancel** closes the entry and changes nothing. The log carries no control for editing or deleting an entry, on this modal or on the table behind it.

## Per-work-order history
Open a work order and select its **Activity Logs** tab. It is the same log, the same three columns, and the same **Log Information** modal, narrowed to that one work order.

IoTFlows builds the tab by searching the log for the work order's identifier, so the tab shows exactly what the organization log shows when you paste that identifier into **Search...**. Use the tab when you already know which work order is in question, and `/logs` when you do not.

The **Activity Logs** tab is also the only version of the log that reaches a phone, because `/logs` itself is absent from both mobile apps. See [Work order detail](/docs/maintain/work-order-detail/).

## See also
- [Work order detail](/docs/maintain/work-order-detail/)
- [Change roles and remove members](/docs/admin/manage-members/)
- [Limit which machines a member can see](/docs/admin/machine-access/)
- [Exports reference](/docs/monitoring/exports-reference/)
