Using Gridline
The audit log
A record of everything that changed, who did it and when, that nobody can edit.
Every time something changes in your company, Gridline writes down who did it, what they did, to what, and when. Nobody can edit or remove those lines, not even an admin. When you need to answer "who changed that?", this is the place. Only admins see Audit log.
Read the log
Open Audit log
In the sidebar, under Company. The newest entries come first.
Narrow it down
Choose What happened (for example “File deleted”), Who did it, and a From and To day, then Apply filters. The address of a filtered log can be bookmarked or sent to a colleague. Choose Older entries at the bottom to go further back.
Open an entry
Choose any line for its details: for example the plan someone changed to, or a file's name.
Each entry shows:
| Field | Meaning |
|---|---|
| Who | The person. Empty for the system (the nightly billing run), or for a person who has since been removed. |
| What | The action, such as file.deleted. |
| To what | The kind of thing it was done to, such as a file or a person. |
| When | The exact time. |
| From where | The caller's address, when the change came over the web. |
| Correlation id | Ties together every entry one request wrote, and matches that request's logs. Quote it to support. |
What is recorded
| Area | Actions |
|---|---|
| Company and account | company.registered, company.activated, company.activation_resent, company.updated, user.profile_updated |
| Sign-in | auth.password_reset_requested, auth.password_reset, auth.password_changed, auth.identity_linked, auth.identity_unlinked |
| People | employee.invited, employee.invite_resent, employee.accepted_invite, employee.disabled, employee.reactivated |
| Plans and billing | subscription.created, subscription.changed, billing.checkout_started, billing.invoice_finalized, billing.payment_failed, billing.payment_succeeded, billing.company_suspended, billing.company_reactivated |
| API keys | api_key.created, api_key.revoked |
| Files | file.uploaded, file.access_changed, file.deleted, report.rebuild_requested |
| Comments | comment.created, comment.updated, comment.deleted |
| Rules | quality_rule.created, quality_rule.updated, quality_rule.deleted |
| Webhooks | webhook_endpoint.created, webhook_endpoint.updated, webhook_endpoint.deleted, webhook_endpoint.secret_rotated, webhook_delivery.redelivered |
The list is closed: an action that is not on it cannot be written, and an automated test checks that every action on it really is. A new feature that changes state has to add its own line here.
You can trust it
- Each entry is written in the same step as the change it describes. If the change is rolled back, so is the entry: nothing is logged that did not happen, and nothing happens without a log line.
- The log is append-only at the database level: the database itself refuses to update or delete a row.
- Entries made by a program say so. An API key's entries carry its id, and an AI agent's say it came through MCP, so you can always tell a person from a script.
New entries also appear on an admin's open screen as they happen, over a live connection.
From code
The log can be read over HTTP with an API key that has the audit scope: see Company and billing API.