Audit Logs

Audit Logs — Know Who Changed What, and When

Track changes to workspace structure and content along with login activity—giving security and compliance teams the trail they need for investigations, access reviews, and audit evidence.

What Is Audit Logs?

Audit Logs is a SmartSuite capability that records changes and access activity across the workspace for security and compliance oversight—changes to SmartSuite structure and content are logged with user and date, and login activity is tracked with source IP address and timestamp. It helps security, IT, and compliance teams answer who did what, when, and from where. Audit Logs are available on the Enterprise plan.

Change Tracking

Log Structural and Content Changes With User and Date

Changes to SmartSuite structure and content are logged with the user who made them and when—so when a permission scheme, Table configuration, or governed record changes, the trail says who and when, not just that it happened.

For compliance teams, that turns "we believe access was controlled" into reviewable history.

Access Oversight

Investigate Login and Provisioning Activity

Login activity is tracked with source IP address and timestamp, giving security teams the raw material for investigating an unexpected sign-in or reconstructing an incident window. SCIM Provisioning adds its own audit logging of provisioning events, so account creation, changes, and removal are documented alongside workspace activity.

For per-record change history—every Field edit on a specific record—SmartSuite's separate Activity History picks up where workspace-level logging leaves off.

Platform Context
How GRC Teams Use

Audit Logs

Every governance framework eventually asks the same question: prove it. Audit Logs give GRC teams the workspace-level record that access reviews, investigations, and audits are built on.

Permission Change Reviews

A compliance team reviews who modified access on a sensitive Solution and when, turning a periodic access-review control into a fast, evidence-backed check.

Anomalous Access Investigation

A risk team spots login activity from an unexpected region and pulls the logged source IP and timestamp to scope the issue. The findings feed the incident record, and the response is documented end to end.

Audit Evidence on Demand

During a SOC 2 or ISO 27001 audit, logged workspace changes with user and date help demonstrate change-management and access-control practices without manual reconstruction.

Offboarding Verification

Compliance confirms that every offboarded account was deprovisioned on schedule by reviewing provisioning activity alongside workspace login records—closing a common user-access-review gap before an auditor raises it.

Workspace Trail Plus Record Trail

Pair Audit Logs with Activity History—workspace-level oversight of structure, access, and logins, plus a per-record log of every Field change for complete traceability.

Works Better Together
Related Features

Every governance framework eventually asks the same question: prove it. Audit Logs give GRC teams the workspace-level record that access reviews, investigations, and audits are built on.

Features FAQ’s
Frequently Asked Questions About
Audit Logs
What are Audit Logs in SmartSuite?

Audit Logs record changes and access activity across the workspace for security and compliance oversight. Changes to SmartSuite structure and content are logged with user and date, and login activity is tracked with source IP address and timestamp.

How are Audit Logs different from Activity History?

Audit Logs provide workspace-level oversight of structural changes and access activity for administrators. Activity History is a per-record change log showing edits to an individual record's Fields, and it is available more broadly across plans.

Do Audit Logs cover login activity?

Yes. Login activity is tracked including source IP address and timestamp, which supports investigating unexpected sign-ins and reconstructing incident timelines.

Is provisioning activity logged too?

Yes—SCIM Provisioning includes its own audit logging and monitoring of provisioning events, so account creation, updates, and removals driven by your identity provider are documented for administrator review.

Which plans include Audit Logs?

Audit Logs are an Enterprise plan feature, per the SmartSuite pricing page. Per-record Activity History is available on other plans with retention that scales by tier.

How do Audit Logs support audit readiness?

Logged changes with user and date, plus login records with IP and timestamp, help teams evidence change-management and access-control practices during SOC 2, ISO 27001, and internal audits—without reconstructing history by hand.

Turn Workspace Activity Into Evidence

Every change logged with a user and a date—so investigations start with facts and audits end with answers.