Get started
1
Open organization settings
Click your organization name in the top left, then select Settings from the dropdown menu.
2
Select Audit log
Click Audit log in the left sidebar.
The audit log requires the organization admin role. Members and guests cannot view audit events.
What gets logged
Ravenna records admin actions that change the configuration of your organization or workspaces. Each event captures the actor, target resource, action, timestamp, and a structured snapshot of the inputs.Events are recorded for areas including:The audit log captures admin configuration changes. Day-to-day ticket activity (comments, status changes, assignments) is recorded on individual tickets, not in the audit log.
Review events
The audit log displays each event as a row with the actor, action, resource, and timestamp.The actor is usually the admin who performed the action. When an integration user sync creates or updates a Ravenna user, the integration itself is the actor. These events appear in the User column with the integration’s name and logo (for example, Okta Sync) instead of a person. The same attribution appears in the detail panel and in CSV exports.Filter events
Use the filter bar above the table to narrow results:Filters combine with
AND logic. Inline text filters save automatically when you click outside the input.Inspect an event
Click any row to open the detail panel. The panel shows:Export events
Export a filtered view of the audit log for offline review or to share with auditors.1
Apply filters
Narrow the audit log to the events you want to export. The export respects your active filters.
2
Open the export menu
Click Export in the top right of the audit log page.
3
Download the file
Ravenna generates a CSV file containing the filtered events and downloads it to your browser.
Exports are scoped to the events visible to you. Events older than your organization’s retention window are not included.
Common use cases
- Investigate an unexpected change. Filter by resource and date range to find the actor and action that produced the change.
- Review admin activity for a user. Filter by actor to see every configuration change a specific admin has made.
- Provide evidence for compliance. Export events for a defined window and share the CSV with auditors.
- Detect failed admin actions. Filter by outcome
failedto identify permission errors or misconfigurations.