You need to know who did what, and when. The audit log is a permanent, searchable record of every significant action taken in your Yaplet account. It covers both what your team does — signing in, changing settings, exporting data — and what Yaplet does on its own, such as the nightly cleanups that remove old conversations. Nobody can edit or delete an entry, including you.
Open the audit log
Go to Settings → Organization settings → Audit Log. Entries are listed newest first. It is not under Security, which trips people up — Security holds the visitor trust scoring, the audit log lives with your organisation's settings.
The audit log comes with a paid plan, from Starter upwards. Free accounts do not have it, and no individual module adds it, so if there is no Audit Log entry in your Settings menu that is why.
What each entry shows
| Column | Description |
|---|---|
| Created | When the action happened |
| Action | What happened (see the list below) |
| User | Which team member did it, or "System" for automated events |
| Resource | The type of thing affected (visitor, member, subscription, and so on) together with the ID of the exact record — click the ID to copy it |
| Location | The country and the IP address the action came from |
Location is hidden until you switch it on. If you are chasing an IP address mid-incident, open the Columns dropdown above the table and tick Location.
What gets logged
- Sign-ins — every sign-in is recorded as
user.signed_in, along with the method used (for example password or Google). - Team and permissions — a member added, updated or removed, and a pending invitation edited before it was accepted.
- Boards and tickets — a board exported, imported, duplicated or deleted, and a ticket deleted.
- Data exports — every CSV export of your organisation's data (
data.exported). - Visitor erasures — every permanent deletion of a visitor's data (
visitor.erased), including how many chats and messages went with it. - Visitor bans — a visitor banned or unbanned (
visitor.banned,visitor.unbanned). - Subscription events — a subscription created, updated, cancelled or reactivated, and modules or volume tiers changed.
- Phone numbers — a number purchased or released.
- Newsletter contacts — contacts imported, exported, bulk-deleted, or moved to a different state.
- Blocked words — every change to your organisation's blocked-word list.
- DPA — the Data Processing Agreement being signed.
- Automatic deletions — the nightly retention cleanups write an entry whenever they remove something: old conversations, empty chat records, and idle anonymous visitors. Because they run every night, this is a routine line item rather than a rarity. See What Yaplet deletes automatically.
Search and filter
Use the search bar to find entries by user, action type, or resource ID. You can also filter by date range to narrow things down to the window an incident happened in.
Retention
Audit log entries are kept for the lifetime of your account and are never deleted automatically — including the entries generated by data erasures. The record saying "visitor erased" survives even though the visitor's own data is gone, which is exactly what makes it useful as proof.
Who can see the audit log
The menu entry and the page are gated on one permission, called Audit Log. Once your plan includes the audit log, owners and admins always have it, because they bypass the per-member permissions. Anyone else sees it only if you switch that permission on for them — so it is not owner-only, and you can give a compliance colleague read access without making them an admin.