# Audit log

Administrators and auditors can view the Audit log. Filter by actor, event type, or date range. **Export CSV** uses the current filters.

![The audit log filtered by actor and event type, with Export CSV](/assets/docs/audit-log.png)

## What is recorded

**Authentication and accounts**

- Sign-in and sign-out
- Second factor enrolled and removed, recovery code used, a challenge exhausted
- Passkey registered and removed
- A step-up that failed

**Users and organization**

- User invited, role changed, removed
- Organization renamed

**Enrollment endpoints** — for each of SCEP, ACME, and EST

- Endpoint created, deleted, enabled, disabled
- Issuance policy changed
- Credentials issued and revoked

**PKI**

- Root CA created, issuing CA created, CA imported
- CA activated, deactivated, retired, rotated, deleted
- Certificate issued — including every SCEP, ACME, and EST enrollment
- Certificate revoked

## Entry details

Each entry includes the actor, action, target, and relevant details such as a serial number, former role, or endpoint name. Administrator actions also include the IP address, user agent, and session.

Background jobs and device enrollments have no actor address.

Entries retain the email address of removed users.

## Notes

- Certificate issuance and CA lifecycle events are recorded on the signing path.
- Individual incorrect second-factor codes are not recorded. Exhausted challenges are.
- _Recovery codes regenerated_ remains available as a filter for historical entries.
- Failed enrollments appear under **Recent enrollments** on the endpoint page, not in the audit log.
