Audit Logs
The Audit Logs page gives administrators a complete, searchable history of security and access events across your organization. It is available at Settings → Audit Logs.
What Is Recorded
Borderbolt automatically records the following events:
| Category | Events |
|---|---|
| Authentication | Sign-in, sign-out, failed sign-in, account locked |
| Devices | New device verified, device revoked, device renamed |
| Security | Suspicious sign-in challenge triggered |
| Users | User created, updated, deleted, status changed |
| Access control | Role changed, permissions changed |
| Credentials | Password changed |
Each event includes the date and time, the user affected, who performed the action, the IP address, and the before/after values where applicable.
Viewing Logs
Navigate to Settings → Audit Logs. You can filter by:
- User — show events for a specific person
- Action — filter to a specific event type (e.g. “Suspicious Login” or “Device Revoked”)
- Date range — narrow to a specific period
- IP address — find events from a specific network
Results are shown 50 per page, ordered newest first.
Exporting Logs
Click Export CSV to download the current filtered view as a spreadsheet. The export includes all matching records up to 10,000 rows and is useful for:
- Evidence submissions to auditors
- Investigating a specific incident
- Sharing with your security team
The export respects your active filters. Apply the date range and user filters you need before clicking Export.
Weekly Security Digest
Every Monday morning, Borderbolt sends a Security Digest email to all Admin users. The digest summarises the past week’s activity:
- Failed sign-in attempts (with week-over-week comparison)
- Suspicious sign-in challenges issued, passed, and failed
- New trusted devices added
- Devices revoked
- Any changes to user MFA settings
You do not need to visit the Audit Logs page to stay on top of security — the digest brings the highlights to your inbox. For anything that looks unusual, use the Audit Logs filters to investigate further.
Log Retention
Audit events are retained for 1 year in the active log and archived for an additional 6 years, giving a total retention of 7 years. Archived records are available on request.
Permissions
Only users with the Settings permission (typically the Admin role) can access the Audit Logs page and export data.
Related
- Security Settings — 2FA, session timeout, IP whitelisting, trusted devices
- User Management — Manage user accounts and roles