Dropstone Support

The organization audit log

Every administrative action in a Dropstone organization is recorded, with filters, ranges, and a CSV or JSON export. What is in it, who can read it, and why nobody can edit it.

Available onFreeProMaxEnterpriseRead by the roles that administer the organization.

Every administrative action in your organization is recorded: who did it, what they did, when, and whether it succeeded. The log is in Audit in the dashboard.


What is in it

  • Who made the change, and when.
  • What they changed: a member's role, a policy, a data setting, a memory shared or withdrawn, an archive read.
  • How it ended: succeeded, refused, or failed.

The log also carries a risk marker and an outcome, so a security review can filter to the actions that deserve attention rather than reading everything.


Read it

Filter by action, by risk, and by outcome, and narrow the range to the last 24 hours, 7 days, 30 days, 90 days, or all time. Then export what you are looking at as CSV or JSON.

The export is the same rows you can see, which is what makes it usable as evidence rather than as a summary of evidence.


Nobody can edit it

The console states it plainly: there is no way to edit or delete a row from here, and there never will be. A mutable audit log is not an audit log.

That is also why the log is exempt from the organization's retention window. The window decides how long conversations, telemetry, and usage records are kept. The record of what happened is kept for the life of the agreement. See How an organization manages its data.


The reads are audited too

Two things worth knowing beyond the settings:

  • Reading the conversation archive writes an entry naming the reader, what they filtered on, and what they searched for. Members can see that their conversations are being recorded, and that the record was read. See Read and export the conversation archive.
  • Changing a data setting is recorded with the name of the person who changed it, and so is the acknowledgement when content logging is turned on.

Who can read it

The roles that administer the organization can read the log, and the auditor role exists for this: it reads everything in the dashboard and changes nothing, which is what an external reviewer or an internal controls team usually needs.

See Roles and permissions.


Related articles

Ctrl+I