Skip to main content

Audit Log

Audit Log

Last verified: 2026-07-08

Awthy's audit log is the display-safe event trail for account security, recovery, policy, support, commerce evidence, export, privacy, and system activity. It is designed to answer who did what, when, to which target, from which source, with what outcome.

Filters and reports

Use filters to narrow by time window, event type, severity, outcome, actor, source, reason category, user, target, and safe search terms. Download reports when you need a bounded support or compliance artifact.

Audit reports should contain sanitized context only. They must not include passwords, authenticator secrets, backup codes, recovery tokens, OAuth tokens, raw cookies, payment details, raw order data, or full request payloads.

Local audit capture is part of Awthy's security model, but broad audit-log viewing, extended retention, and export destinations can depend on plan entitlement. If a panel shows an upgrade state, Awthy should not expose rows, destination credentials, or export controls for that locked capability.

Retention should match the site's plan and compliance needs. Free or lower-tier retention may be shorter than a 12-month audit-history requirement.

Reference lookup and reveal

Some sensitive values are stored as keyed references. The default audit view shows safe labels, hashes, previews, or reference IDs. Revealing a sensitive reference is a deliberate action and should itself be audited.

Reveal only what is necessary for the support or compliance task. Do not paste revealed values into public tickets or screenshots.

Source-IP investigation

Source-IP investigation can summarize event types, related users, actors, and user-agent previews for a source. Treat IP data as operational evidence, not proof of one person. Proxies, VPNs, carrier NAT, and shared offices can all collapse multiple users into one visible address.

Privacy and redaction

Awthy supports WordPress privacy export/erase flows for audit-related personal data, subject to security-log retention needs. Redaction should preserve compliance evidence while removing or anonymizing personal data where required.