View the Audit log


On this page

The Audit log is an organisation-wide record of security and administrative activity in Calibre. It captures who did what, when, and from where, so Admins can review sign-ins, member and role changes, credential and API key activity, billing changes, and more, from a single, centralised view. This gives you a dependable audit trail for compliance, security reviews and investigations, and forms part of Calibre's wider security and compliance practices.

Tip

The Audit log is available on the Company Plan.

The organisation-wide Audit log, listing recent events with the person, action, target, country and device for each one.

The Audit log shows every security and administrative event recorded in your organisation, newest first.

What is recorded#

Each event in the Audit log includes:

  • When: the timestamp the event occurred.
  • Person: the name, email and avatar of the person responsible.
  • Action: what happened, such as Signed in or Member invited.
  • Target: the Site, Team, person or setting the action applied to.
  • Country: the country the request originated from.
  • Device: the browser and operating system used.

Events are grouped into categories so you can quickly narrow down what you are looking for:

  • Sign-ins and sessions
  • Members and provisioning
  • Roles and teams
  • Credentials and security
  • API keys
  • Account
  • Staff access
  • Integrations and SSO
  • Sites, teams and organisation
  • Billing and plan

Within a category you can filter to a single action, such as a failed sign-in attempt, a member invitation, or a session being revoked.

Filter the Audit log#

You can filter the Audit log to focus on exactly the activity you care about.

  • By event type: use the All events dropdown to choose a category or a specific action.
  • By time range: use the All time dropdown to limit results to a period.
  • By person: hover over any row and choose Only this person to see everything that person did.
The event-type filter open on the Audit log, showing categories such as Sign-ins and sessions, Members and provisioning, and Roles and teams, plus specific actions.

Filter by a whole category or a single action using the event-type dropdown.

Hovering over a row in the Audit log reveals an Only this person action to filter the log to a single member.

Hover over any row and choose Only this person to see everything that person did.

Export audit events#

You can download your audit history a month at a time as newline-delimited JSON (NDJSON), with per-month files going back around twelve months. NDJSON is well suited to loading into a data warehouse or analysing with command-line tools.

The Audit log download panel offering monthly NDJSON files for each of the past twelve months.

Download a month of audit events as NDJSON, with files available for the past year.

For other ways to get data out of Calibre, see Export Your Calibre Data.

Stream events to your SIEM#

To keep your security tooling up to date in real time, you can stream every audit event to your SIEM or any HTTPS endpoint using a webhook. Add an endpoint URL and Calibre generates a signing secret beginning with whsec_. Calibre then sends one HTTP POST per audit event, delivered as application/json with a User-Agent of Calibre-Audit-Webhook.

The Audit log webhook settings, showing the endpoint URL, signing secret and a recent deliveries table with event, status, response code and attempts.

Configure an endpoint and signing secret, then review recent deliveries and re-send any that failed.

The recent deliveries table shows each event, its status, the response code and the number of attempts, so you can confirm your endpoint is receiving events. You can re-send a delivery, and enable, disable or remove the webhook at any time.

Verify the signature#

Every request is signed so you can confirm it came from Calibre. Calibre sends a Calibre-HMAC-SHA256-Signature header containing the hex-encoded HMAC-SHA256 of the raw request body, keyed with your signing secret. Compute the signature over the raw request body bytes, before any JSON re-serialisation, and use a constant-time comparison.

Note

This is the same signing scheme as Site webhooks, so one verification implementation covers both. See Webhook security and verification for JavaScript and Ruby examples.

Event payload#

Each delivery contains a single audit event:

Audit event
{
	"type": "audit.event",
	"delivered_at": "2026-06-24T21:59:00Z",
	"data": {
		"id": "4b2e8c9a-1f3d-4a5b-9c7e-2d6f8a0b1c3d",
		"action": "member.role_changed",
		"actor_email": "grace@example.com",
		"actor_label": "Grace Hopper",
		"object_type": "User",
		"object_label": "Alan Turing",
		"country": "Germany",
		"city": "Berlin",
		"region": "Berlin",
		"device": "Safari / iOS",
		"metadata": { "from": "member", "to": "admin" },
		"organisation": "big-co",
		"created_at": "2026-06-24T13:28:00Z"
	}
}

The action is a category.action pair such as member.role_changed. data.id is a stable public UUID for the event, and organisation is your organisation slug. The object_type, object_label, country, city, region and device fields can be null. For privacy, deliveries never include raw IP addresses or full user-agent strings.

Delivery and retries#

  • Calibre sends one POST per event to each enabled endpoint and treats any 2xx response as success.
  • Each attempt times out after 10 seconds. A timeout or non-2xx response counts as a failed delivery.
  • Failed deliveries are retried up to five times with increasing backoff: 1 minute, 5 minutes, 30 minutes, 2 hours, then 6 hours.
  • After 20 consecutive failures the endpoint is disabled automatically and your organisation is emailed. You can re-send failed deliveries from the deliveries table.
  • A retry repeats the same event, so make your endpoint idempotent by de-duplicating on data.id.
  • Delivery history is retained for 90 days.

You can choose how long audit events are kept: 1, 3, 6 or 12 months. If you need to preserve every event during an investigation or to meet a legal or compliance obligation, place a legal hold to retain all audit events regardless of your retention setting until the hold is lifted.

Audit log retention settings, letting you choose how long events are kept and place a legal hold.

Set your retention period, or place a legal hold to preserve every event during an investigation or to meet a compliance obligation.

Who can view the Audit log#

Viewing the Audit log is an Admin-only capability, alongside inviting people and managing billing. For the full breakdown, see User Roles and Permissions.

The Audit log also records the events that other administrative actions generate, including member invitations, role changes and removals and SAML Single Sign-On sign-ins and session revocations.

Have more questions?#

Please contact our friendly, technical support team.