Where to find it
Open Settings → Audit logs. Hobby and Pro see a locked card with an upgrade path. Members can browse; only the workspace owner can export.
LAWDE Shield · Documentation
The audit log is a searchable trail of security-relevant workspace actions. Browse it on Business and Enterprise; CSV and JSON export is owner-only.
Open Settings → Audit logs. Hobby and Pro see a locked card with an upgrade path. Members can browse; only the workspace owner can export.
Actions are written when someone changes access, keys, scrubbers, Beacon, or billing — not for every ingested crash. The filter list in the UI includes:
| Action | When it appears |
|---|---|
| Member invited / removed | Team seat changes |
| API key created / rotated | New or rotated ingest keys |
| Scrubber created / updated / deleted | Custom PII rules |
| .lawdeignore synced / killswitch | Restricted-path file sync or abort override |
| Beacon connected / disconnected | GitHub App mapping |
| Plan upgraded / app renamed | Billing and app identity |
Each row stores time, actor, optional IP and user agent, and a small metadata object. Explore saved-view changes and additional key events are also written even if they are not in the dropdown — leave the action filter on “All actions” to see everything.
Results paginate. Filters also apply to export URLs so the file matches what you see.
Enterprise workspaces can also download the public compliance pack. Related: Enterprise setup · Custom scrubbers · Documentation home