How it works
What it records
The audit trail captures configuration and access changes across the workspace:- API keys: created, deleted, rotated.
- Users: invited, role changed, deleted, logged out.
- Workspace settings: name, discoverability, SSO-required, tracking toggles, guard rails.
- Templates: published, deleted, duplicated, draft created, rolled back, topic changed.
- Brands: created, updated, published, deleted, default changed.
- Automations: template published or deleted.
- Preferences: page published, topic/section created or deleted, channels changed, default status changed.
- Outbound integrations: Segment, Rudderstack, Datadog, and New Relic source changes.
Reading the audit trail
Review events in the console under Settings, or pull them over the API. is cursor-paginated, and reads one. Use the API to forward events to a SIEM, an external log store, or a compliance dashboard.Limits & behavior
- It records configuration changes, not message events. Delivery status lives in message logs.
- Actor and target are always recorded. Every event carries who acted and what changed.
FAQ
Can I pull audit events into my own system?
Can I pull audit events into my own system?
Use to page through events and forward them to a SIEM, log store, or dashboard. Each event includes the actor, target, source, type, and timestamp.
Does the audit trail show message deliveries?
Does the audit trail show message deliveries?
The audit trail records workspace and access changes. For delivery history, use .