Audit logging
Elevale maintains an immutable audit trail for compliance and security accountability.
What is logged
- Workspace data changes (OKRs, KPIs, tasks, wiki, business brief, process map)
- User and role changes
- Permission and custom role modifications
- Admin actions (user deletion, workspace management)
- Account and workspace deletion events
- Data exports and privacy requests
Who can access audit logs
- Workspace admins: Compliance audit log in workspace settings; entries also appear in BD Log (cannot be deleted)
- Platform super admins: System-wide admin audit log
Immutability
Audit log entries are append-only. Users cannot delete audit records from the BD Log timeline. Database RLS restricts write access to audit tables.
Retention
Audit logs are retained for 2 years, then automatically purged. Deletion evidence in data_deletion_log is retained per privacy request policy.
Export
Workspace admins can export audit events as CSV from the Compliance audit log panel.