Who Should Use This Page?
Audit Log is for owners, administrators, and compliance reviewers who need to review account activity, permission changes, exports, failed actions, configuration changes, and period-close activity. It lives at Organization > Audit Log.- Admins use it to investigate access, settings, and workflow questions.
- Managers use it to confirm approvals, denials, exports, and failed actions.
- Finance reviewers use it during month-end, audit prep, and exception review.
- Support teams can ask for the entry ID or entry hash when investigating a specific action.
Before You Start
- You need the View Audit Log permission. The Owner, Admin, Manager, Accountant, and Auditor roles include it by default. Viewing the log, export, compliance reports, and Verify Integrity all use this one permission.
- Without it, Audit Log still shows under Organization in the deck, but opening it, or a link to it, shows Permission Denied instead of the log.
- The User filter also needs View Users, and appears only for the Owner and Admin roles.
- Owners and Admins open the page on entity-wide activity and see the scope controls. Other roles with View Audit Log open the page on their own activity only, and the scope controls are hidden.
Open the Audit Log
- In the deck, choose Organization. Audit Log sits beside Overview, Entities, and Users.
- Select Audit Log. You can also find Audit Log through the command palette navigation search.
- Review the activity chart, summary tiles, date presets, and filters.
- Click a row in the entry table to see the full detail of one event.

Audit Log combines activity volume, severity counts, filter presets, detailed filters, and an activity table in one review surface.
Read the Overview
Start at the top of the page before narrowing the table. The chart and summary tiles help you spot unusual activity spikes, failures, denials, or critical events.- Activity chart: shows the number of entries over the selected window, by hour for short windows and by day for windows longer than three days. The total entry count sits beside the chart. With All time selected, the chart shows the last 24 hours.
- Events: the number of entries that match your filters.
- Critical and Warnings: entries at those severities. Click a tile to filter the table to that severity, and click it again to clear the filter.
- Denied and Failures: entries whose outcome was an access denial or a failure. Click a tile to filter by that outcome, and click it again to clear it.
- Unique users: how many different people appear in the current view.
- Date presets: This hour, This day, This week, This month, All time, or Custom range. The first four are rolling windows that end now: the last hour, the last 24 hours, the last 7 days, and the last 30 days. Custom range shows a from and to date picker.
- Page count: the line under the table shows the page you are on, the number of pages, and how many entries match your filters.
Use Filters
Filters help you move from a large activity history to the exact activity you need. The table and tiles update as soon as you change a filter, and the table returns to page 1.
Use filters to isolate activity by scope, severity, outcome, resource, action, user, IP address, session ID, or text search.
- Jump to my activity: filters the log to your own actions while keeping entity-wide scope. Owners and Admins only. If Arcus cannot identify you in the current session, you see No current user in session; sign out and back in.
- Jump to entity activity: clears the user filter and returns to all entity activity. Owners and Admins only.
- Scope: choose All Activity (Entity-wide) or My Activity Only. Owners and Admins only.
- Severity: All Severities, Info, Notice, Warning, or Critical.
- Outcome: All Outcomes, Success, Failure, or Denied.
- Resource: the types of record or configuration area that appear in your activity, such as orders or users.
- Action: a specific action type, such as a create, update, export, approval, or deletion.
- User: activity from one person. Owners and Admins with View Users only.
- IP address and Session ID: match the exact value you type. The table filters as you type; press Enter or click away to return to page 1.
- Search: searches actions, users, and resource names.
Save Filter Presets
Save filter presets for recurring review jobs. For example, create a preset for failed actions this week, permission changes, data exports, or critical settings activity.- Set the date range and filters you want to reuse.
- Select Save current filters.
- Type a name in Preset name and choose Save. You see Preset saved: followed by the name. Choosing Save with an empty name shows Preset name is required.
- Click the preset chip the next time you need that view. You see Loaded preset: followed by the name.
- Use the trash icon on a chip to delete a stale preset. You see Preset removed.
Open an Audit Entry
Click a table row to open the Audit entry panel. The address changes to that entry’s own link, so you can bookmark or share it. The panel is the best place to review a single event because it shows context beyond the table columns.
The entry drawer provides the detailed context reviewers need for one activity event.
- Header chips: show severity, outcome, and event time.
- Description: summarizes what happened in plain language when available.
- User: shows the person associated with the event, or System for automated activity.
- Resource: shows the area or record affected by the action.
- Changes: shows before and after values when the event has change details.
- Metadata: shows extra event context when available.
- Session: shows IP, session ID, and browser context when available.
- Chain: shows integrity values used to verify that activity history remains consistent.
Share a Deep Link
When you open an audit entry, the browser URL updates to that entry. Copy that URL when another authorized admin needs to review the same event. The other person must still have the View Audit Log permission, and the entry opens when it is in the results their current filters load. Closing the panel returns the address to the Audit Log itself.Export Activity
Use the Export menu when a reviewer needs the current filtered activity outside Arcus. Exports apply the date range, severity, outcome, resource, action, user, and search filters on the page, and search matches entry descriptions only. They do not apply the scope, IP address, or session ID filters.- Export CSV: best for spreadsheet review, sorting, and simple audit packages. The file has Time, User, Action, Resource Type, Resource ID, Severity, Outcome, Description, and IP Address columns.
- Export JSON: best for technical review or structured archival by your internal team.
Run Compliance Reports
Compliance reports are focused CSV downloads for common review questions. Set the date range first, then open the Compliance menu and choose the report type. Compliance reports use the selected date range only. They do not apply the severity, outcome, resource, action, user, or search filters.
Compliance reports turn common review questions into focused downloads using the selected date range.
- User Access Report: sign-ins, failed sign-ins, sign-outs, password changes, completed sign-ups, and expired sessions.
- Permission Changes: role, permission, membership, and user changes, plus access denials. Most of the account access entries described below are in this report, because they are recorded against a user.
- Data Exports: export activity.
- Failed Actions: activity that did not succeed, including denials.
- Config Changes: settings and configuration changes.
- Period Close Activity: accounting close actions.
Verify Integrity
Verify Integrity checks whether the recorded activity chain and archived audit records are still consistent. This is a compliance review tool, not a filter.- Select Verify Integrity. The button shows Verifying while the check runs.
- Wait for the verification to finish.
- Review the result window, titled Integrity verified or Integrity FAILED. It shows Hot entries checked (recent activity), Archives checked, and any Broken archives.
- If the result is not valid, stop relying on exports from that period until an owner or Arcus support reviews it.
- Integrity verified: N hot entries + N archives intact when the chain and every archive check out.
- Chain integrity FAILED, see result for details when a break is found.
- Chain verification failed when the check itself could not run. Try again later.
- Verification returned no result when the check finished without a report. Run it again.
Account Access Entries
When an administrator or a user works on someone’s sign-in, the table shows these entries. The first five are listed in the Action filter. Most are recorded against a user (the Resource column reads user) at Notice severity with a Success outcome, so the Permission Changes report picks them up. Each carries the affected person’s user and email in the Metadata section of the entry panel.What the Page Records
Reviewing the log does not change it, but three actions on this page add their own entries:- Export and each Compliance report add an export entry at Notice severity, with the format and row count, so the Data Exports report shows who exported audit history.
- Verify Integrity adds an entry for every run: Notice with a success outcome when the chain is intact, Critical with a failure outcome when it is not. A successful run also updates the last-verified badge for everyone on the entity.
Common Investigations
- Who changed a setting? Filter by config actions, date range, and search terms from the setting name.
- Why was a user blocked? Filter by user, failed or denied outcome, and the time window of the report.
- Who exported data? Use the Data Exports compliance report or filter by export actions.
- Who changed permissions? Use the Permission Changes compliance report and compare it to User Management.
- Who verified or reset a person’s sign-in? Filter Action by the account access entries above, or use the Permission Changes report.
- What happened during close? Use Period Close Activity and review entries around the close request or approval time.
- Which activity came from one device? Filter by IP address or session ID when that context is available.
Common Blocks
- You cannot open Audit Log: your role does not include View Audit Log. Ask an owner or admin to review your role.
- You only see your own activity: roles other than Owner and Admin open the page on their own activity and cannot switch scope.
- No entries appear: broaden the date range, clear user filters, clear search text, and return to entity activity.
- User filter is missing: the User filter needs the Owner or Admin role and View Users.
- Export has fewer rows than expected: an export holds only as many entries as the table shows per page, newest first, so raise Per page or narrow the filters. A compliance report stops at the 10,000 most recent entries and says so in its first line.
- Compliance report ignores a filter: compliance reports use the date range only.
- A shared link does not open the entry: the entry panel opens only when that entry is on the page of results your current filters load. Widen the date range or clear filters, then open the link again.
- Integrity check fails: preserve the result, avoid overwriting evidence, and escalate to an owner or Arcus support.

