DocumentationGovernance Center

Audit log

The anymize audit log shows without gaps who changed which rule when, who created which key and who revealed clear text, and can be exported as CSV.

5 Min

What the audit log is for

Sooner or later someone asks: the data protection officer, an auditor, a client. The question is almost always the same: who had access, who changed something, and did anyone see clear text. The audit log answers exactly that, in a timeline by day, newest first.

An everyday example: a firm notices that a compliance rule was loosened. The log shows when it happened, who did it and what applied before and after.

What is logged

Eight categories you can also filter by. The first five originate in anymize itself; the last three come from team management.

CategoryWhat it contains
CompliancePolicy changed, policy reset - each with rule, scope and before/after.
GroupsGroup created, edited, deleted, member added or removed.
API keysKey created, shown, renamed, deleted, plus device tokens for clear text.
Sign-inSign-ins, with the method used.
DeanonymizationData deanonymized, anonymization removed, clear text retrieved - each with the number of resolved values.
InvitationsInvitation sent, accepted, declined, expired, withdrawn.
PaymentsPayment succeeded, failed, refunded.
RolesRole changed, role created or deleted, group roles changed.

Each row carries time, action and the acting person. Where there are details, a click expands them: the affected rule, the group name, the changed fields, the number of resolved values.

What is explicitly not logged

The log records actions, not content. That boundary is intentional and matters for both sides.

  • Never the revealed clear text. For “Clear text retrieved” the entry says that it happened and how many values were affected - never which ones. A log of the originals would create exactly the disclosure anymize is meant to prevent.
  • Never individual chat usage. There is no trail of “who chatted when”. Such a trail would be behaviour monitoring and therefore subject to co-determination.
  • Never user data in the before/after fields. Those hold configuration only, for example a switch that went from off to on.

How do I prove who revealed clear text?

Via the “Deanonymization” category. It is why most firms open this log at all. Narrow the time range, click the category, and you see every reveal with time, person and number of resolved values.

For external evidence you export the same range as CSV. What you filtered on screen also applies to the export, so you do not accidentally get something other than what you are reviewing.

Filter, export, retain

  1. 01Choose the time range: 7, 30 or 90 days, or All. Default is 30 days.
  2. 02Click the categories you want - as many as you like. With none selected you see all.
  3. 03Click “Export CSV”. The file name includes the team name and date.

On screen the log shows up to 200 events. If there are more, it says so and asks you to narrow the range. Export goes deeper and covers up to 5,000 rows.

There is no automatic deletion period for these entries; they stay. One exception: if a user account is deleted, that person's entries go with it. If you need to evidence a period permanently, export it and file the file with your records.

If invitations, roles and payments are missing, a yellow notice sits above the list. Then the link to team management is not enabled right now. You still see all other events in full, and the log tells you so instead of silently presenting a gap as “nothing happened”.

Who may read the log

Only Owners and Admins of a team. A regular member does not see the entry and lands on the Compliance page if they open the URL directly. That is not cosmetics: the API behind it checks the same role again.

A solo account sees the entry greyed out with “Team plan only”. The log records actions of people toward other people, and without a team those do not exist.

You always see only your own team. There is no way to switch to another team; the mapping comes from your sign-in, not from the address bar.