Audit logs
Audit logs record the important things that happen inside your Organization — who changed what, and when. They are available on the Business plan and above.
Audit entries are scoped to the Organization. Only Organization owners can view the audit log; other roles (including admin) do not see it.
Scope
Unit Oncall keeps two separate kinds of history, and the Organization audit log is one of them:
- Organization events — actions taken inside your Organization: changes to its members, Teams, Schedules, settings, and integrations. These are what the audit log shows.
- Personal, account-level events — things that belong to a person's account rather than to any one Organization, such as their own sign-in and sign-in failures. These are not tied to an Organization and are not exposed in another party's Organization audit view.
Because a sign-in happens before an Organization is chosen, it belongs to the account layer. What the Organization audit log records instead is the moment a person enters or switches into your Organization — see Organization access below.
What is recorded
The set of recorded events grows as features are added. Today the audit log covers:
| Category | Recorded events |
|---|---|
| Organization access | Selecting your Organization after signing in, switching into it from another Organization, signing out while it is the current Organization, and entry blocked by one of your Organization's own security policies (a locked member, required MFA, required SSO, or required re-authentication). |
| Organization | Creation, name and settings changes, configuration updates and rollbacks, ownership transfer, and deletion request / confirm / cancel / restore. |
| Members | Invitations sent / accepted / revoked / re-sent, members removed or leaving, Organization and Team role changes, Team members added or removed, member lock / unlock, and member configuration updates and rollbacks. |
| Teams & schedules | Team create / update / delete, Schedule create / delete, Schedule configuration updates and operational overrides, absences added / removed / auto-expired, and maintenance windows started / ended / extended. |
| Webhooks | Configuration updates and rollbacks, regenerating a Webhook's credentials, attaching or detaching a transformation rule, and debug mode started / extended / stopped. |
| Resource configuration | Routing-rule configuration updates and rollbacks, transformation-rule create / delete / configuration updates and rollbacks, and bundle-settings configuration updates and rollbacks. |
| Billing | Billing configuration updates and rollbacks. |
| Integrations (MCP) | Connection create / update / delete, connection status and credential changes, connection tests, configuration rollbacks, tool enable / disable, tool tier changes, and attempts to view or change these settings by a member who lacks permission. |
What is not recorded
The following are not part of the Organization audit log today:
- Sign-ins and failed sign-in attempts — these are account-level events (see Scope).
- On-call handovers and alert lifecycle events.
- Read-only activity, such as viewing a Team, a Schedule, or an alert.
Severity
Each entry carries a severity so you can scan for the important ones:
| Severity | Meaning |
|---|---|
INFO | Routine activity, such as entering the Organization or testing an integration connection. |
NOTICE | Creates and updates. |
WARNING | Security-relevant events, such as locking a member, changing integration credentials, or an action that was blocked by a security policy or by insufficient permissions. |
CRITICAL | High-impact actions, such as deletions. |
Reviewing audit logs
As an Organization owner, open the Audit view for your Organization in the console. From there you can:
- Filter by date range.
- Download the page you are currently viewing as CSV or JSON. Each download covers that page only, not the whole history.
Teams, Schedules, webhooks, routing rules, transformation rules, bundle settings, MCP connections, members, and billing each have their own Audit view, showing only the entries for that resource. The Organization-level Audit view is the one that shows every entry.
Each entry includes context such as the actor, the time, and request metadata (for example, the source IP and a request identifier) to help you trace an action.
Related
- Roles and permissions — who can view audit logs and who can perform the recorded actions.
- Organization settings — governance options that generate audit events.
- Domain restriction — another Business-plan governance control.
