Review the organization audit log
Find out who changed something, when they changed it, and what the value was before.
You need to be an Organization Owner or Organization Administrator. See Roles and permissions. Web only, with one exception: the per-work-order history is the version the mobile apps reach.
An audit log is a record of the changes people made, one row per change. IoTFlows writes an entry every time someone creates, edits, or deletes something in your organization, and keeps a copy of the record as it stood before the change and after it.
Use the log to answer "when did this change", not "what is the current state". Rebuilding a machine's current configuration out of a stack of entries is slower and less reliable than opening the machine and reading it. You do not need the log for a value you can read off the screen that owns it.
Open the log
Select Logs in the top navigation, or go to /logs. Each row of the table is one change.
| Column | What it holds |
|---|---|
| Log | A sentence naming the member and what they changed |
| Event | A chip naming the kind of change. The color comes from the server, so one kind of event is always one color |
| Date | When the change was made, as 2:41pm 9/18/25 |
The table pages 25 rows at a time. The footer above and below it reads the position in the result, for example 1 - 25 of 213, with arrows either side to move a page.
The organization audit log. There is no export.
There is no export. The log cannot be downloaded as a CSV and cannot be emailed, so copying the rows you need out of the browser is the only way to take them anywhere else. See What has no export.
Filter by user
- Select the dashed Users pill at the top left.
- Type into Search users... to narrow the list by name, email, or username.
- Select each member whose changes you want. A blue check marks the row.
- Select Apply.
The pill then carries a count of the members you picked, for example Users 2, and the table reloads against that set. To drop the filter, reopen the pill and select Clear, or select the circle at the left of the pill.
Filtering the log by user, date range and free text.
Every filter is written into the address bar, as users, from, to, and text. A filtered log is therefore a link: paste the URL into a ticket and the person who opens it lands on the same rows.
Filter by date range
The button at the top right reads the range it will request, for example 9/15/2025 - 9/21/2025.
- Select the button to open the calendars.
- Pick a preset from the left column: This Week, Last Week, This Month, Last Month, This Year, or Last Year. You can instead type a number of
days up to today, or select a start day and an end day on the two calendars. - Select Apply.
The calendars stop at tomorrow, so you cannot ask for a future range.
The table is empty. Where did the entries go?
Check the date range before anything else. On first load the button reads the last seven days, but no range has been sent yet, so the table holds whatever window the server returns by default.
Selecting Apply is what puts a range on the request, and a range that ends before the change you are looking for returns nothing. A Users filter left applied from an earlier visit is the second thing to check.
Search the text
The Search... field runs under the two filters and re-runs the query on each keystroke. It matches the text of the entry, identifiers included, so pasting a work order's or a machine's identifier returns every entry that touched that record.
Log filters
| Filter | Accepts | Notes |
|---|---|---|
| Users | One or more members, picked from a checkbox list | Search the list by name, email, or username. Takes effect on Apply. Written to the URL as users, once per member |
| Date range | A start day and an end day, from a preset, the days up to today box, or the calendars | Takes effect on Apply. Nothing later than tomorrow. Written to the URL as from and to |
| Search... | Free text | Runs as you type, with no Apply. Matches identifiers as well as words. Written to the URL as text |
The three combine. Picking two members, a one-week range, and the word downtime returns only the entries that satisfy all three.
Read the before-and-after diff
A diff is the same record shown twice, as it stood before a change and as it stood after, so you can compare the two.
Select any row. The Log Information modal opens on the entry's message and two panes of raw JSON:
| Pane | What it holds |
|---|---|
| Before | The whole record as it stood before the change |
| After | The whole record as it stood after it |
Both panes hold the entire record, not only the fields that moved, so read them side by side and find the key that differs. The keys are the API's field names rather than the labels on the screen where the change was made, so a machine's display name reads asset_custom_name.
Not every entry shows a difference. Entries that created a record carry the same JSON in both panes, and so do some status toggles, where the log records the record as it ended up rather than as it stood a moment earlier. On those, the row's own sentence is the record of what changed.
The before-and-after diff for one change.
Why does the close button say Cancel?
Nothing in Log Information is editable and there is nothing to save, so Cancel closes the entry and changes nothing. The log carries no control for editing or deleting an entry, on this modal or on the table behind it.
Per-work-order history
Open a work order and select its Activity Logs tab. It is the same log, the same three columns, and the same Log Information modal, narrowed to that one work order.
IoTFlows builds the tab by searching the log for the work order's identifier, so the tab shows exactly what the organization log shows when you paste that identifier into Search.... Use the tab when you already know which work order is in question, and /logs when you do not.
The Activity Logs tab is also the only version of the log that reaches a phone, because /logs itself is absent from both mobile apps. See Work order detail.




