View the Audit Log
The audit log gives admins a time-stamped record of configuration and account changes across your SparrowDesk account, so you can see who changed what, and when.
The audit log is available on the Enterprise plan, to account admins and super admins.
What the Audit Log Tracks
The audit log records configuration and account-level changes, not day-to-day ticket activity. It covers:
- Logins and logouts, for both agents and admins
- Agent and team changes, including team membership
- Workflows and automation: ticket rules, hourly triggers, SLA policies, and business hours
- Canned responses and their folders
- Knowledge base categories, folders, and articles
- Channel integrations: email, WhatsApp, Facebook, Instagram, and SMS
- Company records
- Account and subscription: plan changes, billing contact, and API keys
- Security settings: SSO, IP allowlist, session timeout, and password policy
Changes made automatically by a rule or system process are logged too, with the actor shown as System. The log does not record actions on individual tickets, such as who replied to or closed a specific ticket.
Open the Audit Log
Go to Settings → Security → Audit Log. The log opens on the last 30 days, the newest first. Each row shows the timestamp, who performed the action, their actor type, the module, the action taken, and a short summary of what changed.

Read an Entry
Each row describes a single change in plain language. The What Changed column summarises what happened, such as a knowledge base article being created or updated, and names the item affected. Alongside it, each entry shows the action taken, who performed it, the timestamp, the module the change belongs to, and the IP address the person acted from.
In the example below, the What changed filter is set to KB article, so the log shows only knowledge base changes.

Filter the Log
Select Filter in the top-right to narrow the list by:
- Time period: the last 7, 30, or 90 days, the last 12 months, or a custom range
- Performed by: any agent or admin, or System for automated changes
- What changed: one or more modules from the list above
Export the Log
Select Export in the top-right to download the log as CSV or Excel. Choose a time period and at least one module, then export. Timestamps in exported files use UTC.
How Long Entries Are Kept
The audit log keeps the last 12 months in the app. Older history stays available through the audit log API with no time cap, and any file you export is a permanent snapshot.
FAQ
- Can I see the IP address behind a change?
Yes. Each entry made by a person includes the IP address they acted from. Entries made by the System have no IP address. - What time zone are the timestamps in?
The in-app log uses your account time zone. Exported files and the API use UTC. - Why do some entries show "System" as the actor?
When an automation or system process makes a configuration change, the log records the actor as System. Filter by System to see only those changes. - Can the audit log alert me when something changes?
No. The audit log is a record you review, not an alerting tool. It does not send notifications when a change happens. - How do I get history older than 12 months?
The in-app view holds 12 months. For older records, use the audit log API, which keeps the full history, or keep the files you export, which do not expire.
