Audit trail
The audit trail is an append-only record of privileged actions in your organization (settings, key, credential, member, and role changes, sign-ins, and exports) for compliance reviews and “who changed this?”. Inference requests are in the request logs instead.
View and export
Open Settings → Audit trail in the dashboard, filter by date, event type, and member, and Export CSV to download the filtered set. There is no API or streaming export. Both need View audit trail, which all four built-in roles include. Each export is recorded as AUDIT_LOG_EXPORTED and appears in the file it produces.
The CSV columns are Timestamp, User Name, User Email, Role, IP Address, Event Type, and Event Description. Cells starting with =, +, -, @, a tab, or a carriage return get a leading single quote so spreadsheets don’t run them as formulas.
Entry fields
Entries are never edited and are kept indefinitely. Failed actions write no entry (it commits with the change), except failed sign-ins (LOGIN_FAILED).
Reference
Event type names are the prefix plus the action, for example API_KEY_CREATED. The Event type filter lists every current type; new features add more.
Changes under Security → Prompt injection write no entry. Project and customer PI overrides do, as PROJECT_PI_SETTINGS_* and CUSTOMER_PI_SETTINGS_*.
A deleted member’s entries keep the name, email, and role captured at write time. A deleted organization’s entries can no longer be listed.