---
description: Audit Log coverage, operation grouping, IP handling, retention, and the effects of backup and restore.
---

# Audit Log

Administrators can review major activity under **Audit Log**. Access requires
the administrator-only `audit.read` capability. Each record identifies the
actor, time, action, target, and recorded result.

## Recorded Activity

| Area | Coverage |
| --- | --- |
| Authentication | Successful sign-in, explicit sign-out, and sensitive-action reauthentication |
| Accounts | Invitations, activation, access recovery, deletion, role/status/password changes, MFA changes, and explicit session revocation |
| Content | Post/Page publication-state changes, Trash, restore, permanent deletion, and Media deletion |
| Publishing and settings | GitHub publish results, settings saves, and credential changes |
| Imports | WXR chunk results and final settings application |
| Operations | Database upgrades, backups, restores, administrator recovery, content clearing, resets, Edge operations, and search rebuilds |

Routine editing, autosaves, reads, connection tests, rejected authentication,
and scheduled maintenance are not recorded. Individual comment, form, and
newsletter actions are outside this record set. Bulk operations produce a
summary per request rather than one record per row.

Results distinguish success, failure, partial success, unchanged data, and an
unconfirmed outcome. A WXR chunk or operation start does not mean the whole
workflow completed.

## Actors and Grouped Operations

Records preserve the actor's ID, name, and email as a snapshot, so deleted
accounts remain identifiable and searchable. Target names and summaries also
describe the action at the time it was recorded.

Search-index rebuilds appear once in the list with their latest recorded
result. Open the record to inspect start, progress, and completion or failure.
Date and result filters use the latest event; actor and IP filters also match
earlier steps.

For work spanning requests, the initial actor is separate from the caller and
connection that performed each step. Token-only operations use the actor label
**Operations token**.

## Connection Information and Retention

| Data | Retention |
| --- | --- |
| Audit records | 365 days |
| Original IP addresses in audit records | 30 days |
| IP hashes, User-Agent, available location and ASN | With the record, up to 365 days |

IP addresses follow Studio's verified
[client IP policy](../../operations/maintenance-and-recovery/index.md#client-ip).
Location and ASN come from Cloudflare request metadata; Studio does not call an
external geolocation service. Missing information remains unavailable.

IP hashes use a versioned HMAC with a key derived for audit IPs from
`STUDIO_AUTH_SECRET`. They support finding records for the same address without
keeping its original text indefinitely. Replacing the secret changes later
hashes. If hashing fails, Studio omits the original IP as well.

Scheduled cleanup removes expired data, and reads apply the same retention
limits even when cleanup is delayed. These limits apply to the live audit
store, not copies already exported in backups or a logging platform's retention.

## Privacy and Availability

Records omit passwords, tokens, content bodies, and external response bodies.
Settings events record field names and credential-change indicators rather
than values.

Saving the audit record happens in the background. A recording failure does
not undo the original action, and a record may be missing. Audit Log is an
administrative history, not a tamper-proof ledger: database owners can alter
the database, and restoration can rewind its history.

## Database Operations

Clear Content and Reset Studio preserve audit records. SQL backups include
them; a Studio restore returns history to the backup's point in time and
records completion after verification. New audit writes are paused during
that restore so they do not interfere with restored data.

Uninstall removes the audit table. Its completion remains in
[Worker operational logs](../../operations/logs/index.md). Older activity is
not reconstructed when an installation upgrades to a schema with Audit Log.
