The Audit log is an organisation-wide record of security and administrative activity in Calibre. It captures who did what, when, and from where, so Admins can review sign-ins, member and role changes, credential and API key activity, billing changes, and more, from a single, centralised view. This gives you a dependable audit trail for compliance, security reviews and investigations, and forms part of Calibre's wider security and compliance practices.
The Audit log is available on the Company Plan.

The Audit log shows every security and administrative event recorded in your organisation, newest first.
What is recorded#
Each event in the Audit log includes:
- When: the timestamp the event occurred.
- Person: the name, email and avatar of the person responsible.
- Action: what happened, such as Signed in or Member invited.
- Target: the Site, Team, person or setting the action applied to.
- Country: the country the request originated from.
- Device: the browser and operating system used.
Events are grouped into categories so you can quickly narrow down what you are looking for:
- Sign-ins and sessions
- Members and provisioning
- Roles and teams
- Credentials and security
- API keys
- Account
- Staff access
- Integrations and SSO
- Sites, teams and organisation
- Billing and plan
Within a category you can filter to a single action, such as a failed sign-in attempt, a member invitation, or a session being revoked.
Filter the Audit log#
You can filter the Audit log to focus on exactly the activity you care about.
- By event type: use the All events dropdown to choose a category or a specific action.
- By time range: use the All time dropdown to limit results to a period.
- By person: hover over any row and choose Only this person to see everything that person did.

Filter by a whole category or a single action using the event-type dropdown.

Hover over any row and choose Only this person to see everything that person did.
Export audit events#
You can download your audit history a month at a time as newline-delimited JSON (NDJSON), with per-month files going back around twelve months. NDJSON is well suited to loading into a data warehouse or analysing with command-line tools.

Download a month of audit events as NDJSON, with files available for the past year.
For other ways to get data out of Calibre, see Export Your Calibre Data.
Stream events to your SIEM#
To keep your security tooling up to date in real time, you can stream every audit event to your SIEM or any HTTPS endpoint using a webhook. Add an endpoint URL and Calibre generates a signing secret beginning with whsec_. Calibre then sends one HTTP POST per audit event, delivered as application/json with a User-Agent of Calibre-Audit-Webhook.

Configure an endpoint and signing secret, then review recent deliveries and re-send any that failed.
The recent deliveries table shows each event, its status, the response code and the number of attempts, so you can confirm your endpoint is receiving events. You can re-send a delivery, and enable, disable or remove the webhook at any time.
Verify the signature#
Every request is signed so you can confirm it came from Calibre. Calibre sends a Calibre-HMAC-SHA256-Signature header containing the hex-encoded HMAC-SHA256 of the raw request body, keyed with your signing secret. Compute the signature over the raw request body bytes, before any JSON re-serialisation, and use a constant-time comparison.
This is the same signing scheme as Site webhooks, so one verification implementation covers both. See Webhook security and verification for JavaScript and Ruby examples.
Event payload#
Each delivery contains a single audit event:
{
"type": "audit.event",
"delivered_at": "2026-06-24T21:59:00Z",
"data": {
"id": "4b2e8c9a-1f3d-4a5b-9c7e-2d6f8a0b1c3d",
"action": "member.role_changed",
"actor_email": "grace@example.com",
"actor_label": "Grace Hopper",
"object_type": "User",
"object_label": "Alan Turing",
"country": "Germany",
"city": "Berlin",
"region": "Berlin",
"device": "Safari / iOS",
"metadata": { "from": "member", "to": "admin" },
"organisation": "big-co",
"created_at": "2026-06-24T13:28:00Z"
}
}The action is a category.action pair such as member.role_changed. data.id is a stable public UUID for the event, and organisation is your organisation slug. The object_type, object_label, country, city, region and device fields can be null. For privacy, deliveries never include raw IP addresses or full user-agent strings.
Delivery and retries#
- Calibre sends one POST per event to each enabled endpoint and treats any
2xxresponse as success. - Each attempt times out after 10 seconds. A timeout or non-
2xxresponse counts as a failed delivery. - Failed deliveries are retried up to five times with increasing backoff: 1 minute, 5 minutes, 30 minutes, 2 hours, then 6 hours.
- After 20 consecutive failures the endpoint is disabled automatically and your organisation is emailed. You can re-send failed deliveries from the deliveries table.
- A retry repeats the same event, so make your endpoint idempotent by de-duplicating on
data.id. - Delivery history is retained for 90 days.
Retention and legal hold#
You can choose how long audit events are kept: 1, 3, 6 or 12 months. If you need to preserve every event during an investigation or to meet a legal or compliance obligation, place a legal hold to retain all audit events regardless of your retention setting until the hold is lifted.

Set your retention period, or place a legal hold to preserve every event during an investigation or to meet a compliance obligation.
Who can view the Audit log#
Viewing the Audit log is an Admin-only capability, alongside inviting people and managing billing. For the full breakdown, see User Roles and Permissions.
The Audit log also records the events that other administrative actions generate, including member invitations, role changes and removals and SAML Single Sign-On sign-ins and session revocations.
Have more questions?#
Please contact our friendly, technical support team.