Audit Log
The Audit Log is the record of every change made to your account. It answers three questions about any change: when it happened, what moved, who did it. You will find it in the dashboard at Dashboard, then Audit Log.
It is enabled on every plan. There is nothing to switch on.
1 - What is recorded
Guardr records a row whenever something changes on your account, whichever way that change reached us. Six routes can change an account. All six are recorded:
| Source | What it covers |
|---|---|
| Dashboard | Anything you or a browser session does in the Guardr dashboard. |
| API | Calls made with one of your API keys. |
| WordPress plugin | Changes made by a site running the Guardr WordPress plugin. |
| Enrollment | A site joining your account by redeeming an enrollment token. |
| Billing | Plan changes our billing provider reports, such as a payment or a cancellation. |
| Guardr operator | A change made by Guardr staff acting on your account. |
Sign-ins are recorded too, alongside password resets and email verification, so the log covers who reached the account as well as what they changed.
Operator actions are visible to you. When Guardr staff act on your account the row says so. We decided that showing those rows is worth more than hiding them.
2 - What each row shows
| Part of the row | What it tells you |
|---|---|
| When | The time of the change, shown in the time zone set on your account. |
| What | One sentence describing the change, with the thing it happened to beside it. |
| Source | How the change reached us, from the six routes above. |
| Who | Named only when it is not you. A change you made from the dashboard does not repeat your own address on every row. A change made by an API key, a plugin, an agent, our billing provider or a Guardr operator names which one. |
| Before and after | Rows that changed a value carry a Show detail button. It opens a small table with the old value beside the new one, one line per field that moved. |
The name of the thing a row concerns is a link. Following it narrows the log to that one site, status page or key, which is how you read the history of a single thing. The expanded detail carries a second link that opens the thing itself.
3 - What is not recorded
The Audit Log records CHANGES YOU OR SOMETHING ACTING FOR YOU MADE. It is not a copy of everything Guardr does. The following are left out on purpose, because they are produced by our own website health monitoring rather than by anybody changing your account:
- Scan results. The outcome of a scan. The moment a scan was STARTED is recorded, because somebody asked for it. What the scan then found is not.
- Uptime checks. The individual checks behind your uptime figures.
- Aggregation. The hourly and daily rollups built from those checks.
- Email bookkeeping. Delivery records for the mail we send you.
- Rate-limit counters. The counters behind API and scan limits.
Those five would bury the changes you are looking for under machine-written rows that nobody decided. Your scan history lives on each site page. Your uptime history lives on the same page beside it.
4 - Filters and search
The page opens on the last thirty days. Three controls sit above the list:
- Search matches the name of the thing, the sentence describing the change, the action name. It is a plain text match rather than a query language.
- Source narrows to one of the six routes above.
- Date range offers the last seven, thirty or ninety days. A custom range takes your own two dates.
More filters opens three more: the type of thing that changed, the exact action, then whether the row carries a before and after. The dropdowns only offer values your own account has actually produced, so a choice always has rows behind it.
Every filter is held in the page address. A filtered view is therefore a link you can save or send to somebody else inside your organisation. It opens on exactly the same view.
5 - CSV export
Download CSV exports the view you are looking at, with the same filters and the same search applied. The file opens in any spreadsheet.
An export carries at most 5000 rows. When your filtered view holds more than that, the newest 5000 are exported and the older rows are left out. Narrow the date range or add a filter to bring a large account inside the cap.
6 - How long history is kept
Guardr keeps 90 days of account history, on every plan. Free and paid are the same here. Rows older than ninety days are deleted each night and cannot be recovered.
The page states the date before which nothing is kept, so you always know where the record starts. Export anything you need to hold for longer.
Deleting your Guardr account deletes its audit log with everything else. We do not claim the log is tamper-evident, because destroying it by closing the account is a supported thing to do.
7 - What the log cannot tell you
An empty stretch has more than one explanation. If you look at a period and find no rows, that can mean nothing happened. It can also mean the rows were older than ninety days so have been deleted. The page cannot yet tell those two apart for you.
The retention date at the foot of the page is the thing to read first. Anything before it is outside the window we keep, so an empty stretch there says nothing about whether the account was quiet. An empty stretch after it, inside the window, is a genuinely quiet period.
We would rather say this plainly than let an empty list look like a statement about your account.
Try it on your site - free
Free scan, no signup required. Upgrade when you need alerts, history or PDF reports.
Scan your site →