Audit Log

Track important actions across your organization — user changes, board and ticket deletions, data exports, visitor erasures, subscription events, changes made by AI, and more.

Overview

The Audit Log gives you a searchable record of significant actions that happen in your Yaplet organization. Every entry captures who did what, when, and from where — helping you stay on top of security, compliance, and team activity. You'll find it at Settings → Organization settings → Audit Log.

Viewing the Audit Log requires the Settings.AuditLog permission.

What Gets Logged

Yaplet automatically records events such as:

  • User actions — logins, permission changes, profile updates
  • Data operations — CSV exports, visitor erasures
  • Boards — a board being exported (including whether the reporter's personal details and the activity logs were included in the file), imported, duplicated or deleted
  • Tickets — a ticket deleted, or a whole column cleared. Only deletions are recorded here; everyday ticket edits and moves are not written to the Audit Log
  • Subscription events — plan changes, billing updates
  • API keys — a key created, regenerated or deleted, and a key's AI access (MCP) setting changed ("API key AI access changed")
  • Changes made by AI — every change, delete and send that Copilot or a connected AI app (through the MCP server) makes in your account, shown as AI change or, in red, AI delete or send. See below
  • Automated processes — the nightly data-retention cleanups, logged as "System": expired conversations, expired Copilot conversations, empty conversations and idle visitors

Log Entry Details

Each audit log entry includes:

FieldDescription
CreatedWhen the action occurred
UserEmail of the user who performed the action, or "System" for automated events
ActionThe type of action (e.g., data.exported, visitor.erased, board.deleted, tickets.deleted, data_retention.auto_delete)
Resource typeThe kind of resource affected (e.g., visitor, export, chat, board, board_tickets)
Resource IDThe specific resource identifier
IPThe IP address of the user
CountryThe country the request originated from

Changes made by AI

Whenever Copilot or a connected AI app creates, updates, deletes or sends something, one entry is written here:

  • User — the person the AI acted for: the person using Copilot, the person who connected the app, or the person who switched the API key's AI access on
  • Action — AI change for creating and updating, AI delete or send for a permanent delete or a message to someone outside your team
  • Metadata (open the entry) — the action's name and plain title (for example tickets.update, "Update ticket") and the connection: copilot, the app's name, or the API key's name
  • Resource type / Resource ID — the record the AI acted on

The values the AI sent are not stored in the entry, because they can contain personal data. Reads — anything the AI only looked at — are not logged.

Shift changes are tracked separately

Changes to a shift are not written here — apart from the AI change entry above when an AI made them. Each shift keeps its own history — who changed what, and the old and new value — which you open from the shift itself. That history also covers shift changes made through Copilot or a connected MCP client: they are attributed to the signed-in person and marked as coming from "Yaplet Copilot (MCP)", so an assistant can never make an untraceable change.

Filtering and Sorting

Use the built-in filters to narrow down log entries:

  • Action — search by action type
  • User email — filter by who performed the action
  • Resource type — filter by the kind of resource involved

The log is sorted by date (newest first) by default.