The Audit log shows who did what in your Bridge organisation, and when. Use it to review user activity, gather evidence for audits and investigate security incidents.
Accessing the Audit log
Open Audit log from the main menu. It's available to Organisation admins and shows activity for your organisation only.
If you don't see the Audit log page, contact us.
What is recorded
Each entry shows the time, who performed the action (a user, an API client or the system) and what happened. Expand an entry for more details, including the IP address where available.
The Audit log covers:
Users: users added, updated, deleted, locked, unlocked or reactivated; role and investigation category changes; password changes and resets; two-factor authentication changes
Investigations: investigations created, participants added, messages sent, internal notes, conclusions, template changes
Data retention: investigation retention setting changes and each clean-up
Entity sharing: entities reported, updated, deleted, approved or rejected; query matches
Forum: posts and replies
Organisation: API clients created or deleted, encryption key changes, terms and conditions accepted
Filtering
Narrow the list by date range, by action type, or by searching for a person. Search matches both who performed an action and who it was performed on.
Audit data outside Bridge
If you need audit log data for an audit, an incident investigation or your SIEM, contact us.
