The customer audit log is a record of what happens in your workspace: access and configuration changes, and the integration tool calls Viktor makes. Your workspace owns the trail and exports it through the Public API. The **Audit Logs** page also shows the approval history for protected actions.

## Who can use it

Audit logs need all of the following:

- An **Enterprise** workspace. See [Plans and credits](/docs/plans-and-credits).
- An **admin** role. The **Audit Logs** tab is hidden from members.

If your workspace is not eligible, the **Audit Logs** tab does not appear in Settings. Opening [app.viktor.com/settings/audit-logs](https://app.viktor.com/settings/audit-logs) directly shows "Customer audit logs are not available for this workspace yet."

## Turn on audit logging

1. Open **Settings** and select **Audit Logs** (or go to [app.viktor.com/settings/audit-logs](https://app.viktor.com/settings/audit-logs)).
2. Select **Enable Audit Logs**. Viktor confirms with **Audit logging enabled**.
3. Choose a **Capture Level** (see below).

The page shows:

- **Status**: **Enabled** or **Disabled**.
- **Capture health**: **Healthy** or **Degraded**. When capture is degraded, a warning shows since when, and the latest capture error.

To stop recording, select **Disable Audit Logs**. Turning audit logging on or off, and changing the capture level, are themselves recorded as events.

## Choose a capture level

The **Capture Level** card appears while audit logging is on:

- **Full**: "Access and configuration changes plus all data activity: tool calls, data in, data out."
- **Governance only**: "Access and configuration changes only. Data activity is not recorded."

Switching to **Governance only** asks you to confirm. New data activity stops being recorded and can't be recovered later. Events already recorded are kept until they expire. Access and configuration changes are always recorded. Switching back to **Full** loses nothing.

If you turn audit logging off and on again, it comes back at the capture level you chose before.

## What gets recorded

Examples of events in the trail:

- **Team changes**: invites created and revoked, role changes and member removals, including refused attempts. See [Team members and roles](/docs/team-members-and-roles).
- **Audit settings**: enabling or disabling the log and changing the capture level.
- **API keys**: a key being created, edited, having its scopes changed, rotated, revoked or deleted.
- **Refused API key use**: a request refused because the key was missing a scope, inactive, expired, had the wrong secret, or belonged to a disabled user. These events include the client IP address and browser or client type. Repeated refusals for the same key and reason are grouped rather than recorded one by one.
- **Audit exports**: a key reading the audit log through the API. Access to the trail is part of the trail.
- **Data activity** (with **Full** capture): integration tool calls, and the data going in and out.

## Export audit events

There is no download button in the app. The **Pull API** card explains: "Audit events are available only through the public API. Create a team API key with audit read access, then poll the events endpoint with the returned cursor."

1. Open [Settings → API Keys](https://app.viktor.com/settings/api-keys) and create a **Team API key** with the `audit:read` scope. Only admins can create team keys, and `audit:read` can't be added to a personal key.
2. Call `GET /api/public/v1/audit/events` with the key.
3. Pass each response's `next_cursor` as the next request's `cursor` query parameter until you have every page.

`GET /api/public/v1/audit/digests` returns daily integrity digests, so you can check that no event was added, removed or edited. The request details are in the [Public API](/docs/public-api) reference. Audit logging must be enabled for the export to work.

## How long events are kept

Audit events are kept for 400 days, then deleted.

## Approval history

Below the audit settings, **Approval history** lists "every action a teammate approved or rejected, with who decided, where, the policy in force, the resulting status, and a link to the originating message." Each record shows **Decided by**, **Response from**, **Policy at decision**, **Policy at execution**, **Decided at** and **Executed at**, plus the proposed arguments.

Approval history appears on the same page, for the same admins and Enterprise workspaces. If nothing has been approved or rejected yet, it shows **No approvals yet**. See [Approvals](/docs/approvals) for how approvals work.

## Limits by plan and permission

| | Requirement |
| --- | --- |
| See the **Audit Logs** tab | Admin, Enterprise workspace |
| Enable, disable, change capture level | Admin, Enterprise workspace |
| Export events and digests | Team API key with `audit:read`, audit logging enabled |
| Retention | 400 days |

## Common problems

- **No Audit Logs tab**: you are not an admin, or your workspace is not on Enterprise. See [Enterprise plans](/help/category/billing-subscription/enterprise-plans).
- **"Customer audit logs are not available for this workspace yet."**: the same cause, reached through a direct link.
- **The export returns 403**: use a team key, not a personal key, and make sure it has `audit:read` and that audit logging is enabled. The [Public API](/docs/public-api) lists the error codes.
- **Capture health shows Degraded**: check the capture error on the page. If it continues, contact support with your **Team ID** from [Team settings](https://app.viktor.com/settings/team/settings).
- **Missing tool-call events**: check the capture level. **Governance only** does not record data activity, and events from before a switch back to **Full** can't be recovered.

## Related

- [Public API](/docs/public-api)
- [Approvals](/docs/approvals)
- [Team members and roles](/docs/team-members-and-roles)
- [Settings overview](/docs/settings-overview)
- [Data and privacy](/docs/data-and-privacy)