Using Gridline

The audit log

A record of everything that changed, who did it and when, that nobody can edit.

Every time something changes in your company, Gridline writes down who did it, what they did, to what, and when. Nobody can edit or remove those lines, not even an admin. When you need to answer "who changed that?", this is the place. Only admins see Audit log.

Read the log

  1. Open Audit log

    In the sidebar, under Company. The newest entries come first.

  2. Narrow it down

    Choose What happened (for example “File deleted”), Who did it, and a From and To day, then Apply filters. The address of a filtered log can be bookmarked or sent to a colleague. Choose Older entries at the bottom to go further back.

  3. Open an entry

    Choose any line for its details: for example the plan someone changed to, or a file's name.

Each entry shows:

FieldMeaning
WhoThe person. Empty for the system (the nightly billing run), or for a person who has since been removed.
WhatThe action, such as file.deleted.
To whatThe kind of thing it was done to, such as a file or a person.
WhenThe exact time.
From whereThe caller's address, when the change came over the web.
Correlation idTies together every entry one request wrote, and matches that request's logs. Quote it to support.

What is recorded

AreaActions
Company and accountcompany.registered, company.activated, company.activation_resent, company.updated, user.profile_updated
Sign-inauth.password_reset_requested, auth.password_reset, auth.password_changed, auth.identity_linked, auth.identity_unlinked
Peopleemployee.invited, employee.invite_resent, employee.accepted_invite, employee.disabled, employee.reactivated
Plans and billingsubscription.created, subscription.changed, billing.checkout_started, billing.invoice_finalized, billing.payment_failed, billing.payment_succeeded, billing.company_suspended, billing.company_reactivated
API keysapi_key.created, api_key.revoked
Filesfile.uploaded, file.access_changed, file.deleted, report.rebuild_requested
Commentscomment.created, comment.updated, comment.deleted
Rulesquality_rule.created, quality_rule.updated, quality_rule.deleted
Webhookswebhook_endpoint.created, webhook_endpoint.updated, webhook_endpoint.deleted, webhook_endpoint.secret_rotated, webhook_delivery.redelivered

The list is closed: an action that is not on it cannot be written, and an automated test checks that every action on it really is. A new feature that changes state has to add its own line here.

You can trust it

  • Each entry is written in the same step as the change it describes. If the change is rolled back, so is the entry: nothing is logged that did not happen, and nothing happens without a log line.
  • The log is append-only at the database level: the database itself refuses to update or delete a row.
  • Entries made by a program say so. An API key's entries carry its id, and an AI agent's say it came through MCP, so you can always tell a person from a script.

New entries also appear on an admin's open screen as they happen, over a live connection.

From code

The log can be read over HTTP with an API key that has the audit scope: see Company and billing API.