The audit log: who did what, when — and how to export it
Every administrative and access event across all products, filterable by date and category, downloadable as CSV, and available on the API.
- 1Open it from any product's Settings → Audit log (owners and administrators). Filter by date range and category, then Download CSV for auditors, insurers, or your own records.
- 2What it records: team invites, joins, role changes and removals; remote-wipe privilege grants and revocations; response actions (isolate, release, wipe, scans); API keys created and revoked; every read-only Cybermatic support session and every managed-service-provider access; data exports and deletion scheduling; Trust Center settings and document changes and NDA approvals; SSO activation; connections added.
- 3Each row has the UTC time, the event, the actor (who did it), the target (who or what it affected), and detail. Events are written at the moment they happen and cannot be edited or deleted from the portal.
- 4Automate it: the customer API exposes the same data at /api/v1/audit (JSON with cursor paging, or ?format=csv) — useful for pulling the log into your own SIEM or GRC tool on a schedule.
Tip: Insurers and SOC 2 auditors typically ask for 'evidence of access review' — a quarterly CSV of the Team and Support categories answers it directly.