Skip to main content

Audit log

See who did what, and when, in your Bridge organisation.

The Audit log shows who did what in your Bridge organisation, and when. Use it to review user activity, gather evidence for audits and investigate security incidents.


Accessing the Audit log

Open Audit log from the main menu. It's available to Organisation admins and shows activity for your organisation only.

If you don't see the Audit log page, contact us.


What is recorded

Each entry shows the time, who performed the action (a user, an API client or the system) and what happened. Expand an entry for more details, including the IP address where available.

The Audit log covers:

  • Users: users added, updated, deleted, locked, unlocked or reactivated; role and investigation category changes; password changes and resets; two-factor authentication changes

  • Investigations: investigations created, participants added, messages sent, internal notes, conclusions, template changes

  • Data retention: investigation retention setting changes and each clean-up

  • Entity sharing: entities reported, updated, deleted, approved or rejected; query matches

  • Forum: posts and replies

  • Organisation: API clients created or deleted, encryption key changes, terms and conditions accepted


Filtering

Narrow the list by date range, by action type, or by searching for a person. Search matches both who performed an action and who it was performed on.


Audit data outside Bridge

If you need audit log data for an audit, an incident investigation or your SIEM, contact us.

Did this answer your question?